PYSEC-2018-59

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/trytond/PYSEC-2018-59.yaml
JSON Data
https://api.test.osv.dev/v1/vulns/PYSEC-2018-59
Aliases
Published
2018-04-12T15:29:00Z
Modified
2024-04-29T11:26:38.122673Z
Summary
[none]
Details

The safeeval function in trytond in Tryton before 2.4.15, 2.6.x before 2.6.14, 2.8.x before 2.8.11, 3.0.x before 3.0.7, and 3.2.x before 3.2.3 allows remote authenticated users to execute arbitrary commands via shell metacharacters in (1) the collection.domain in the webdav module or (2) the formula field in the pricelist module.

References

Affected packages

PyPI / trytond

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.4.0
Fixed
2.4.15
Introduced
2.6.0
Fixed
2.6.14
Introduced
2.8.0
Fixed
2.8.11
Introduced
3.2.0
Fixed
3.2.3
Introduced
3.0.0
Fixed
3.0.7

Affected versions

2.*

2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.6.0
2.6.1
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.10
2.6.11
2.6.12
2.6.13
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
2.8.10

3.*

3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.2.0
3.2.1
3.2.2