Bug 1131707 (CVE-2019-10868) - VUL-1: CVE-2019-10868: tryton: an authenticated user can order records based on a field for which he has no access
Summary: VUL-1: CVE-2019-10868: tryton: an authenticated user can order records based ...
Status: RESOLVED FIXED
Alias: CVE-2019-10868
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 42.3
Hardware: Other Other
: P4 - Low : Minor (vote)
Target Milestone: ---
Assignee: Axel Braun
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/228999/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2019-04-05 14:07 UTC by Alexandros Toptsoglou
Modified: 2023-02-12 16:25 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexandros Toptsoglou 2019-04-05 14:07:13 UTC
CVE-2019-10868

In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19,
4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6, an authenticated
user can order records based on a field for which he has no access right. This
may allow the user to guess values.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-10868
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10868
https://hg.tryton.org/trytond/rev/f58bbfe0aefb
https://discuss.tryton.org/t/security-release-for-issue8189/1262
Comment 1 Alexandros Toptsoglou 2019-04-05 14:07:56 UTC
TW --> 4.6.16 not affected
LEAP 15/42.3 -->4.2.19 affected
Comment 2 Axel Braun 2019-04-05 14:18:42 UTC
(In reply to Alexandros Toptsoglou from comment #1)
> TW --> 4.6.16 not affected

TW *is* affected as well!

will wai for gnuhealth-client (affected as well...) and update all together
Comment 3 Swamp Workflow Management 2019-04-10 11:00:14 UTC
This is an autogenerated message for OBS integration:
This bug (1131707) was mentioned in
https://build.opensuse.org/request/show/692918 Factory / tryton
https://build.opensuse.org/request/show/692919 15.1 / tryton
Comment 4 Swamp Workflow Management 2019-04-10 14:10:07 UTC
This is an autogenerated message for OBS integration:
This bug (1131707) was mentioned in
https://build.opensuse.org/request/show/692948 42.3 / tryton
https://build.opensuse.org/request/show/692949 15.0 / tryton
Comment 6 Swamp Workflow Management 2019-04-16 19:40:07 UTC
This is an autogenerated message for OBS integration:
This bug (1131707) was mentioned in
https://build.opensuse.org/request/show/694857 42.3 / tryton
https://build.opensuse.org/request/show/694858 15.0 / tryton
Comment 7 Swamp Workflow Management 2019-04-20 08:20:07 UTC
This is an autogenerated message for OBS integration:
This bug (1131707) was mentioned in
https://build.opensuse.org/request/show/696161 Factory / gnuhealth-client
https://build.opensuse.org/request/show/696162 15.1 / gnuhealth-client
Comment 8 Swamp Workflow Management 2019-04-23 20:30:08 UTC
This is an autogenerated message for OBS integration:
This bug (1131707) was mentioned in
https://build.opensuse.org/request/show/697279 15.0 / tryton
https://build.opensuse.org/request/show/697280 42.3 / tryton
Comment 9 Swamp Workflow Management 2019-05-06 19:09:45 UTC
openSUSE-RU-2019:1335-1: An update that fixes one vulnerability is now available.

Category: recommended (low)
Bug References: 1131707
CVE References: CVE-2019-10868
Sources used:
openSUSE Leap 15.0 (src):    tryton-4.2.24-lp150.2.18.1
Comment 10 Swamp Workflow Management 2019-05-06 19:10:08 UTC
openSUSE-RU-2019:1334-1: An update that fixes one vulnerability is now available.

Category: recommended (low)
Bug References: 1131707
CVE References: CVE-2019-10868
Sources used:
openSUSE Leap 42.3 (src):    tryton-4.2.24-35.1
Comment 11 Swamp Workflow Management 2019-05-08 10:10:16 UTC
openSUSE-RU-2019:1340-1: An update that fixes one vulnerability is now available.

Category: recommended (low)
Bug References: 1131707
CVE References: CVE-2019-10868
Sources used:
openSUSE Backports SLE-15 (src):    tryton-4.2.24-bp150.2.14.1
Comment 12 Tomáš Chvátal 2019-07-11 11:40:53 UTC
This is automated batch bugzilla cleanup.

The openSUSE 42.3 changed to end-of-life (EOL [1]) status. As such
it is no longer maintained, which means that it will not receive any
further security or bug fix updates.
As a result we are closing this bug.

If you can reproduce this bug against a currently maintained version of 
openSUSE (At this moment openSUSE Leap 15.1, 15.0 and Tumbleweed) please
feel free to reopen this bug against that version (!you must update the
"Version" component in the bug fields, do not just reopen please), or
alternatively create a new ticket.

Thank you for reporting this bug and we are sorry it could not be fixed
during the lifetime of the release.

[1] https://en.opensuse.org/Lifetime
Comment 13 Marcus Meissner 2019-07-12 06:15:22 UTC
was fixed
Comment 14 OBSbugzilla Bot 2023-02-12 16:25:04 UTC
This is an autogenerated message for OBS integration:
This bug (1131707) was mentioned in
https://build.opensuse.org/request/show/1064690 Factory / gnuhealth-client