# Security Release for issue #13142

**URL:** https://discuss.tryton.org/t/security-release-for-issue-13142/7196
**Category:** News
**Tags:** security
**Created:** [April 17, 2024, 4:00pm UTC](https://discuss.tryton.org/t/security-release-for-issue-13142/7196 "2024-04-17T16:00:16Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [April 17, 2024, 4:00pm UTC](https://discuss.tryton.org/t/security-release-for-issue-13142/7196/1 "2024-04-17T16:00:16Z")

</div>

[Cédric Krier](https://foss.heptapod.net/ced) has found that [trytond](https://pypi.org/project/trytond/) [accepts compressed content from unauthenticated requests](https://foss.heptapod.net/tryton/tryton/-/issues/13142) which makes it vulnerable to [zip bomb](https://en.wikipedia.org/wiki/Zip_bomb) attacks.

## Impact

[CVSS v3.0 Base Score: 5.3](https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:F/RL:O/RC:C/MAV:N/MAC:L/MPR:N/MUI:N/MS:U/MC:N/MI:N/MA:N)

- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality: None
- Integrity: None
- Availability: Low

## Workaround

A proxy can be deployed in front of the `trytond` server to forbid this kind of request.

## Resolution

All affected users should upgrade `trytond` to the latest version.

Affected versions per series:

- `trytond`:
  - 7.0: \<= 7.0.9
  - 6.8: \<= 6.8.14
  - 6.0: \<= 6.0.44

Non affected versions per series:

- `trytond`:
  - 7.0: \>= 7.0.10
  - 6.8: \>= 6.8.15
  - 6.0: \>= 6.0.45

## Reference

- [Accept request with gzip content encoding may make server vulnerable to zip bomb (#13142) · Issues · Tryton / Tryton · GitLab](https://bugs.tryton.org/13142)

## Concerns?

Any security concerns should be reported on the bug-tracker at [https://bugs.tryton.org/](https://bugs.tryton.org/) with the confidential checkbox checked.

---

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [April 18, 2024, 8:16am UTC](https://discuss.tryton.org/t/security-release-for-issue-13142/7196/2 "2024-04-18T08:16:48Z")

</div>

A post was merged into an existing topic: [Tarball signatures](https://discuss.tryton.org/t/tarball-signatures/7204/2)

---

<div class="post-metadata">

### Author: ![system](https://discuss-cdn.tryton.org/uploads/default/original/1X/c6f8ec0a40525cdcd50058c734283450a4b3d38b.png) [@system](https://discuss.tryton.org/u/system)
#### Post date: [May 17, 2024, 4:00pm UTC](https://discuss.tryton.org/t/security-release-for-issue-13142/7196/3 "2024-05-17T16:00:53Z")

</div>

This topic was automatically closed after 30 days. New replies are no longer allowed.
