CVE-2022-26662

unknown
Published 2022-03-11 · Modified 2024-11-21
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v2
VIR risk

Description

An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4, and 6.1.x and 6.2.x through 6.2.1. An unauthenticated user can send a crafted XML-RPC message to consume all the resources of the server.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2022-26662

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed6.0.5-1
debian debianbullseyefixed5.0.8-1+deb11u1
debian debianforkyfixed6.0.5-1
debian debiansidfixed6.0.5-1
debian debiantrixiefixed6.0.5-1

Package impact

EcosystemPackageVulnerableFixed
python PyPItrytond>=5.0.0,<5.0.465.0.46
python PyPItrytond>=6.0.0,<6.0.166.0.16
python PyPItrytond>=6.1.0,<6.2.66.2.6
python PyPIproteus>=5.0.0,<5.0.125.0.12
python PyPIproteus>=6.0.0,<6.0.56.0.5
python PyPIproteus>=6.1.0,<6.2.26.2.2
python PyPItryton>=6.2.0,<5.0.465.0.12

References

Verify integrity in audit chain (admin only). AS-IS.