CVE Published: 04/04/2017 |
CVE Updated: 05/08/2024 |
CVE Year: 2017 Source: debian |
Vendor: n/a |
Product: tryton-server before 3.4.0-3+deb8u3 Status : PUBLISHED
CVE-2017-0360 Description
file_open in Tryton 3.x and 4.x through 4.2.2 allows remote authenticated users with certain permissions to read arbitrary files via a "same root name but with a suffix" attack. NOTE: This vulnerability exists because of an incomplete fix for CVE-2016-1242.