{"id":"UBUNTU-CVE-2025-66424","details":"Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.","modified":"2026-01-20T18:42:05.981784Z","published":"2025-11-30T03:15:00Z","upstream":["CVE-2025-66424"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-66424"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2025-66424"},{"type":"REPORT","url":"https://discuss.tryton.org/t/security-release-for-issue-14366/8953"},{"type":"REPORT","url":"https://foss.heptapod.net/tryton/tryton/-/issues/14366"}],"affected":[{"package":{"name":"tryton-server","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/tryton-server@3.8.3-1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.6.2-1","3.6.3-2","3.6.3-3","3.8.0-1","3.8.1-1","3.8.2-1","3.8.3-1"],"ecosystem_specific":{"binaries":[{"binary_name":"tryton-server","binary_version":"3.8.3-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-66424.json"}},{"package":{"name":"tryton-server","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/tryton-server@4.6.3-2?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.4.3-3","4.6.0-1","4.6.1-1","4.6.2-1","4.6.3-2"],"ecosystem_specific":{"binaries":[{"binary_version":"4.6.3-2","binary_name":"tryton-server"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-66424.json"}},{"package":{"name":"tryton-server","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/tryton-server@5.0.16-1?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.0.10-1","5.0.14-2","5.0.16-1"],"ecosystem_specific":{"binaries":[{"binary_name":"tryton-server","binary_version":"5.0.16-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-66424.json"}},{"package":{"name":"tryton-server","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/tryton-server@6.0.12-1?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.0.33-2","6.0.9-3","6.0.12-1"],"ecosystem_specific":{"binaries":[{"binary_version":"6.0.12-1","binary_name":"tryton-server"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-66424.json"}},{"package":{"name":"tryton-server","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/tryton-server@6.0.39-1?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["6.0.34-1","6.0.36-1","6.0.39-1"],"ecosystem_specific":{"binaries":[{"binary_version":"6.0.39-1","binary_name":"tryton-server"},{"binary_name":"tryton-server-all-in-one","binary_version":"6.0.39-1"},{"binary_name":"tryton-server-nginx","binary_version":"6.0.39-1"},{"binary_name":"tryton-server-postgresql","binary_version":"6.0.39-1"},{"binary_name":"tryton-server-uwsgi","binary_version":"6.0.39-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-66424.json"}},{"package":{"name":"tryton-server","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/tryton-server@7.0.30-1?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.0.24-1","7.0.30-1"],"ecosystem_specific":{"binaries":[{"binary_name":"tryton-server","binary_version":"7.0.30-1"},{"binary_name":"tryton-server-all-in-one","binary_version":"7.0.30-1"},{"binary_name":"tryton-server-nginx","binary_version":"7.0.30-1"},{"binary_name":"tryton-server-postgresql","binary_version":"7.0.30-1"},{"binary_name":"tryton-server-uwsgi","binary_version":"7.0.30-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-66424.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}]}