4.3
CVE-2025-66422
- EPSS 0.28%
- Veröffentlicht 30.11.2025 00:00:00
- Zuletzt bearbeitet 07.10.2026 20:10:01
- Erkennungen
Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.203 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| MITRE | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-402 Transmission of Private Resources into a New Sphere ('Resource Leak')
The product makes resources available to untrusted parties when those resources are only intended to be accessed by the product.
https://discuss.tryton.org/t/security-release-for-issue-14354/8950
https://foss.heptapod.net/tryton/tryton/-/issues/14354