CVE-2019-10868: Debian Linux

Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.

In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6, an authenticated user can order records based on a field for which he has no access right. This may allow the user to guess values.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Tryton Trytond: from 4.2.0, before 4.2.21 (fixed in 4.2.21); from 4.4.0, before 4.4.19 (fixed in 4.4.19); from 4.6.0, before 4.6.14 (fixed in 4.6.14); from 4.8.0, before 4.8.10 (fixed in 4.8.10); from 5.0.0, before 5.0.6 (fixed in 5.0.6)

Published 2019-04-05. Last modified 2026-06-17.