PT-2016-4664 · Tryton · Tryton

Published

2016-08-30

·

Updated

2022-05-17

·

CVE-2016-1241

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Tryton versions 3.x before 3.2.17 Tryton versions 3.4.x before 3.4.14 Tryton versions 3.6.x before 3.6.12 Tryton versions 3.8.x before 3.8.8 Tryton versions 4.x before 4.0.4
Description The issue allows remote authenticated users to discover user password hashes.
Recommendations For Tryton versions 3.x before 3.2.17, update to version 3.2.17 or later. For Tryton versions 3.4.x before 3.4.14, update to version 3.4.14 or later. For Tryton versions 3.6.x before 3.6.12, update to version 3.6.12 or later. For Tryton versions 3.8.x before 3.8.8, update to version 3.8.8 or later. For Tryton versions 4.x before 4.0.4, update to version 4.0.4 or later.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-1241
DSA-3656-1
GHSA-52J9-V3JC-9XGC
PYSEC-2016-12
PYSEC-2016-40

Affected Products

Tryton