XML Entity Expansion Vulnerability in Tryton Application Platform
CVE-2022-26662

7.5HIGH

Key Information:

Vendor

Tryton

Vendor
CVE Published:
10 March 2022

What is CVE-2022-26662?

An XML Entity Expansion (XEE) issue has been identified in the Tryton Application Platform that allows unauthenticated users to craft malicious XML-RPC messages. These messages can exploit the vulnerability to consume server resources, potentially leading to denial of service. The vulnerable versions include specific releases of both the Tryton Server and the Command Line Client (proteus), highlighting the need for immediate updates for affected users to ensure system integrity and availability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

EPSS Score

5% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.