Security Release for issue 14907

Cédric Krier has discovered that access is not enforced when browsing record instances in template.

Impact

CVSS v3.0 Base Score: 6.5

  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality: High
  • Integrity: None
  • Availability: None

Workaround

There is no workaround.

Resolution

All affected users should upgrade trytond, marketing_automation and marketing_email to the latest version.

Affected versions per series:

  • trytond:
    • 8.0: <= 8.0.5
    • 7.8: <= 7.8.11
    • 7.0: <= 7.0.52
  • markting_automation:
    • 8.0: <= 8.0.0
    • 7.8: <= 7.8.2
    • 7.0: <= 7.0.3
  • marketing_email:
    • 8.0: <= 8.0.0
    • 7.8: <= 7.8.2
    • 7.0: <= 7.0.2

Not affected versions per series:

  • trytond:
    • 8.0: >= 8.0.6
    • 7.8: >= 7.8.12
    • 7.0: >= 7.0.53
  • markting_automation:
    • 8.0: >= 8.0.1
    • 7.8: >= 7.8.3
    • 7.0: >= 7.0.4
  • marketing_email:
    • 8.0: >= 8.0.1
    • 7.8: >= 7.8.3
    • 7.0: >= 7.0.3

Reference

Concerns?

Any security concerns should be reported on the bug-tracker at https://bugs.tryton.org/ with the confidential checkbox checked.