Skip to main content

Transmission of Private Resources into a New Sphere ('Resource Leak')

CVE-2025-66422

Severity Medium
Score 4.3/10

Summary

Tryton trytond versions 6.0 prior to 6.0.70, 7.0.x prior to 7.0.40, 7.4.x prior to 7.4.21, and 7.6.x prior to 7.6.11 allow remote attackers to obtain sensitive trace-back (server setup) information.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • LOW
  • LOW
  • NONE

CWE-402 - Transmission of Private Resources into a New Sphere ('Resource Leak')

The software makes resources available to untrusted parties when those resources are only intended to be accessed by the software.

Advisory Timeline

  • Published