CVE-2022-26662
HIGH7.5EPSS 5.6%XML Entity Expansion in trytond and proteus
發布日:2022/3/11修改日:2026/4/28
描述
An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4, and 6.1.x and 6.2.x through 6.2.1. An unauthenticated user can send a crafted XML-RPC message to consume all the resources of the server.
受影響套件(5)
- Debian/tryton-proteusfrom 0, < 5.0.8-1+deb11u1
- Debian/tryton-serverfrom 0, < 5.0.33-2+deb11u1
- PyPI/proteus>= 5.0.0, < 5.0.12
- PyPI/tryton>= 5.0.0, < 5.0.12, >= 6.0.0, < 6.0.5, >= 6.2.0, < 6.2.2, < 6.2.6, < 6.0.16, < 5.0.46
- PyPI/trytond>= 5.0.0, < 5.0.46
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
參考連結(9)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2022-26662
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2022-26662
- PATCHhttps://hg.tryton.org/trytond
- WEBhttps://bugs.tryton.org/issue11244
- WEBhttps://discuss.tryton.org/t/security-release-for-issue11219-and-issue11244/5059
- WEBhttps://lists.debian.org/debian-lts-announce/2022/03/msg00016.html
- WEBhttps://lists.debian.org/debian-lts-announce/2022/03/msg00017.html
- WEBhttps://www.debian.org/security/2022/dsa-5098
- WEBhttps://www.debian.org/security/2022/dsa-5099