Security Release for issues #13505 and #13506Albert Cervera has found that trytond allows to execute reports for records that user has no read access and also for reports limited to a set of group that the user is not. Impact
WorkaroundThere is no known workaround. ResolutionAll affected users should upgrade Affected versions per series:
Non affected versions per series:
ReferenceConcerns?Any security concerns should be reported on the bug-tracker at https://bugs.tryton.org/ with the confidential checkbox checked. 2 posts - 2 participants |
[tryton-announces] Security Release for issues #13505 and #13506
News - Tryton Discussion: ced Sun, 04 May 2025 09:07:19 -0700
