CVE-2012-0215 - Windowless Rushes
Description
model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model which allows remote authenticated users to modify the privileges of arbitrary users via a (1) create (2) write (3) delete or (4) copy rpc call.
Reference
http://www.debian.org/security/2012/dsa-2444 http://news.tryton.org/2012/03/security-releases-for-all-supported.html https://bugs.tryton.org/issue2476 http://hg.tryton.org/trytond/rev/8e64d52ecea4