SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-1242

file_open in Tryton before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allows remote authenticated users with certain permissions to read arbitrary files via the name parameter or unspecified other vectors.

MEDIUM 4.4EPSS 1.83%

Does this matter?

Lower severity and a low EPSS score (1.83%). Track it; it rarely justifies an emergency change on its own.

Description

file_open in Tryton before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allows remote authenticated users with certain permissions to read arbitrary files via the name parameter or unspecified other vectors.

CVSS 3.0
4.4 MEDIUMCVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
EPSS
1.83% probability · 78th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
tryton/tryton
Source
security@debian.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.