Security Release for issues #13505 and #13506Albert Cervera has found that trytond allows to execute reports for records that user has no read access and also for reports limited to a set of group that the user is not. Impact
WorkaroundThere is no known workaround. ResolutionAll affected users should upgrade Affected versions per series:
Non affected versions per series:
ReferenceConcerns?Any security concerns should be reported on the bug-tracker at https://bugs.tryton.org/ with the confidential checkbox checked. 1 post - 1 participant |
[tryton-announces] Security Release for issues #13505 and #13506
News - Tryton Discussion: ced Mon, 16 Sep 2024 23:12:13 -0700
- [tryton-announces] Security Release for issu... News - Tryton Discussion: ced
- [tryton-announces] Security Release for... News - Tryton Discussion: ced
