Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.
{
"binaries": [
{
"binary_name": "tryton-server",
"binary_version": "6.0.39-1"
},
{
"binary_name": "tryton-server-all-in-one",
"binary_version": "6.0.39-1"
},
{
"binary_name": "tryton-server-nginx",
"binary_version": "6.0.39-1"
},
{
"binary_name": "tryton-server-postgresql",
"binary_version": "6.0.39-1"
},
{
"binary_name": "tryton-server-uwsgi",
"binary_version": "6.0.39-1"
}
]
}{
"binaries": [
{
"binary_name": "tryton-server",
"binary_version": "7.0.30-1"
},
{
"binary_name": "tryton-server-all-in-one",
"binary_version": "7.0.30-1"
},
{
"binary_name": "tryton-server-nginx",
"binary_version": "7.0.30-1"
},
{
"binary_name": "tryton-server-postgresql",
"binary_version": "7.0.30-1"
},
{
"binary_name": "tryton-server-uwsgi",
"binary_version": "7.0.30-1"
}
]
}