Bug 1213869 - VUL-0: trytond: security release 6.0.34
Summary: VUL-0: trytond: security release 6.0.34
Status: RESOLVED FIXED
: 1214682 (view as bug list)
Alias: None
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.4
Hardware: Other Other
: P3 - Medium : Normal (vote)
Target Milestone: ---
Assignee: Axel Braun
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/373887/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-08-01 13:39 UTC by Carlos López
Modified: 2023-08-28 12:22 UTC (History)
2 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Carlos López 2023-08-01 13:39:19 UTC
Edbo 3 and Cédric Krier have found that record rules are not enforced 2 by trytond when only reading fields without an SQL type (like Function fields).

Affected versions per series:
  trytond:
    6.8: <= 6.8.2
    6.6: <= 6.6.10
    6.0: <= 6.0.33
    5.0: <= 5.0.59

Non affected versions per series:
  trytond:
    6.8: >= 6.8.3
    6.6: >= 6.6.11
    6.0: >= 6.0.34
    5.0: >= 5.0.60

References:
https://discuss.tryton.org/t/security-release-for-issue-12428/6397
https://foss.heptapod.net/tryton/tryton/-/issues/12428
Comment 1 Carlos López 2023-08-01 13:40:16 UTC
We have:
- openSUSE:Backports:SLE-15-SP4:Update/trytond: 6.0.32
- openSUSE:Backports:SLE-15-SP5:Update/trytond: 6.0.32

Already submitted for Factory.
Comment 2 Axel Braun 2023-08-01 17:37:17 UTC
https://build.opensuse.org/request/show/1101630
Comment 3 Axel Braun 2023-08-01 17:38:14 UTC
(In reply to Carlos López from comment #1)
> 
> Already submitted for Factory.

Once it is in Factory, I will push it to Backports
Comment 4 Marcus Meissner 2023-08-06 19:06:38 UTC
openSUSE-SU-2023:0209-1: An update that contains security fixes can now be installed.

Category: security (moderate)
Bug References: 1213869
CVE References: 
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP5 (src):    trytond-6.0.34-bp155.2.6.1
Comment 5 Marcus Meissner 2023-08-06 19:07:09 UTC
openSUSE-SU-2023:0208-1: An update that contains security fixes can now be installed.

Category: security (moderate)
Bug References: 1213869
CVE References: 
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP4 (src):    trytond-6.0.34-bp154.2.30.1
Comment 6 Axel Braun 2023-08-07 06:28:40 UTC
As fixes are submitted we can closed the bug
Comment 7 Axel Braun 2023-08-28 12:22:17 UTC
*** Bug 1214682 has been marked as a duplicate of this bug. ***