CVE-2019-10868

In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6, an authenticated user can order records based on a field for which he has no access right. This may allow the user to guess values.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
mitreCNA
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AC:L/AV:N/A:N/C:L/I:N/PR:L/S:U/UI:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 51%
VendorProductVersion
trytontrytond
4.2.0 ≤
𝑥
< 4.2.21
trytontrytond
4.4.0 ≤
𝑥
< 4.4.19
trytontrytond
4.6.0 ≤
𝑥
< 4.6.14
trytontrytond
4.8.0 ≤
𝑥
< 4.8.10
trytontrytond
5.0.0 ≤
𝑥
< 5.0.6
debiandebian_linux
9.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
tryton-server
bullseye (security)
5.0.33-2+deb11u2
fixed
bullseye
5.0.33-2+deb11u2
fixed
jessie
not-affected
bookworm
6.0.29-2+deb12u2
fixed
bookworm (security)
6.0.29-2+deb12u3
fixed
trixie
6.0.53-1
fixed
sid
7.0.19-6
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
tryton-server
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
ignored
jammy
needed
impish
ignored
hirsute
ignored
groovy
ignored
focal
needed
eoan
ignored
disco
ignored
cosmic
not-affected
bionic
not-affected
xenial
not-affected
trusty
dne