Security Release for issue #14947

Cédric Krier has discovered that Tryton does not prevent weasyprint to access local files when rendering HTML report to PDF.

Impact

CVSS v3.0 Base Score: 4.9

  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality: High
  • Integrity: None
  • Availability: None

Workaround

There is no workaround.

Resolution

All affected users should upgrade trytond to the latest version.

Affected versions per series:

  • trytond:
    • 8.0: <= 8.0.7
    • 7.8: <= 7.8.13
    • 7.0: <= 7.0.54

Not affected versions per series:

  • trytond:
    • 8.0: >= 8.0.8
    • 7.8: >= 7.8.14
    • 7.0: >= 7.0.55

Some custom reports may fail after the upgrade because they are using local files. Such reports must be updated to use only files via public HTTP.

Reference

Concerns?

Any security concerns should be reported on the bug-tracker at https://bugs.tryton.org/ with the confidential checkbox checked.