Information on source package tryton-server

Available versions

ReleaseVersion
jessie3.4.0-3+deb8u3
stretch4.2.1-2+deb9u2
buster5.0.4-2+deb10u3
bullseye5.0.33-2+deb11u2
bookworm6.0.29-2+deb12u3
trixie6.0.53-1
sid7.0.19-7

Open issues

BugjessiestretchbusterbullseyebookwormtrixiesidDescription
TEMP-0000000-FDAB26vulnerablevulnerablefixedfixedfixedfixedfixedTransaction cache overrides the current user
TEMP-0000000-0477AAvulnerablevulnerablevulnerablefixedfixedfixedfixedget_groups does not always returns the group of the action
TEMP-0000000-9BB4B1vulnerablevulnerablefixedfixedfixedfixedfixedtryton-server lack of record validation
TEMP-0000000-9B1564vulnerablevulnerablefixedvulnerable (no DSA)fixedfixedfixedtryton zipbomb DoS
TEMP-0000000-4F0A4AvulnerablevulnerablevulnerablefixedfixedfixedfixedAccess to records of report are not checked
CVE-2022-26662vulnerablefixedfixedfixedfixedfixedfixedAn XML Entity Expansion (XEE) issue was discovered in Tryton Applicati ...
CVE-2022-26661vulnerablefixedfixedfixedfixedfixedfixedAn XXE issue was discovered in Tryton Application Platform (Server) 5. ...

Resolved issues

BugDescription
CVE-2019-10868In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 befo ...
CVE-2017-0360file_open in Tryton 3.x and 4.x through 4.2.2 allows remote authentica ...
CVE-2016-1242file_open in Tryton before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3 ...
CVE-2016-1241Tryton 3.x before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3. ...
CVE-2015-0861model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4 ...
CVE-2014-6633The safe_eval function in trytond in Tryton before 2.4.15, 2.6.x befor ...
CVE-2012-2238trytond 2.4: ModelView.button fails to validate authorization
CVE-2012-0215model/modelstorage.py in the Tryton application framework (trytond) be ...

Security announcements

DSA / DLADescription
DSA-5776-1tryton-server - security update
DLA-3853-1tryton-server - security update
DLA-3547-1tryton-server - security update
DSA-5482-1tryton-server - security update
DLA-2945-1tryton-server - security update
DSA-5098-1tryton-server - security update
DSA-4426-1tryton-server - security update
DSA-3826-1tryton-server - security update
DLA-882-1tryton-server - security update
DLA-607-1tryton-server - security update
DSA-3656-1tryton-server - security update
DSA-3425-1tryton-server - security update
DLA-70-1tryton-server - security update
DSA-3043-1tryton-server - security update
DSA-2444-1tryton-server - privilege escalation

Search for package or bug name: Reporting problems