lizparadox_ has discovered that the report name can be used to execute commands on the server.
Impact
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: High
- User Interaction: Required
- Scope: Unchanged
- Confidentiality: High
- Integrity: High
- Availability: High
Workaround
There is no workaround.
Resolution
All affected users should upgrade trytond to the latest version.
Affected versions per series:
trytond:- 8.0: <= 8.0.10
- 7.8: <= 7.8.16
Not affected versions per series:
trytond:- 8.0: >= 8.0.11
- 7.8: >= 7.8.17
Reference
Concerns?
Any security concerns should be reported on the bug-tracker at https://bugs.tryton.org/ with the confidential checkbox checked.