PT-2022-17993 · Unknown · Tryton Application Platform
Jeremy Mousset
·
Published
2022-03-07
·
Updated
2022-03-18
·
CVE-2022-26661
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Tryton Application Platform (Server) versions 5.x through 5.0.45
Tryton Application Platform (Server) versions 6.x through 6.0.15
Tryton Application Platform (Server) versions 6.1.x through 6.2.5
Tryton Application Platform (Command Line Client (proteus)) versions 5.x through 5.0.11
Tryton Application Platform (Command Line Client (proteus)) versions 6.x through 6.0.4
Tryton Application Platform (Command Line Client (proteus)) versions 6.1.x through 6.2.1
Description
An XXE issue was discovered, allowing an authenticated user to make the server parse a crafted XML SEPA file to access arbitrary files on the system.
Recommendations
For Tryton Application Platform (Server) versions 5.x through 5.0.45, update to a version later than 5.0.45.
For Tryton Application Platform (Server) versions 6.x through 6.0.15, update to a version later than 6.0.15.
For Tryton Application Platform (Server) versions 6.1.x through 6.2.5, update to a version later than 6.2.5.
For Tryton Application Platform (Command Line Client (proteus)) versions 5.x through 5.0.11, update to a version later than 5.0.11.
For Tryton Application Platform (Command Line Client (proteus)) versions 6.x through 6.0.4, update to a version later than 6.0.4.
For Tryton Application Platform (Command Line Client (proteus)) versions 6.1.x through 6.2.1, update to a version later than 6.2.1.
As a temporary workaround, consider restricting access to XML SEPA file parsing until a patch is available.
Exploit
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tryton Application Platform