-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Mon, 24 Nov 2025 20:27:26 +0100
Source: tryton-sao
Binary: tryton-sao
Architecture: source all
Version: 7.0.28+ds1-1+deb13u2
Distribution: trixie-security
Urgency: high
Maintainer: Debian Tryton Maintainers <team+tryton-team@tracker.debian.org>
Changed-By: Mathias Behrle <mathiasb@m9s.biz>
Description:
tryton-sao - Tryton application platform - web client
Changes:
tryton-sao (7.0.28+ds1-1+deb13u2) trixie-security; urgency=high
.
* Add 02_escape_completion_content.patch.
Patch for security issue:
https://foss.heptapod.net/tryton/tryton/-/issues/14363
Stored XSS Vulnerability Found in Party Field Leading to Arbitrary
JavaScript Execution
S.a. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1121233
Checksums-Sha1:
168b90f3d031910425e74c7aec17ef1a7db735d1 2101 tryton-sao_7.0.28+ds1-1+deb13u2.dsc
6c90839a73bed621eafca51946b70b89aa16b5e0 1554772 tryton-sao_7.0.28+ds1.orig.tar.xz
78a6c2edadaba5dae50c4e12b25f4f2eccfab4a5 39096 tryton-sao_7.0.28+ds1-1+deb13u2.debian.tar.xz
7dfdd11e9c50d02642a1145d178b12e6b5c1aa09 1644600 tryton-sao_7.0.28+ds1-1+deb13u2_all.deb
382c7bea5cdcdbef3aac772e726815c00f95405d 8515 tryton-sao_7.0.28+ds1-1+deb13u2_amd64.buildinfo
Checksums-Sha256:
59aac3f5c07b22dd3a6f4b3ef33f679427534eb96491aff897629af53339ac32 2101 tryton-sao_7.0.28+ds1-1+deb13u2.dsc
c21fff02d657e90fbddfbfc9fb980232d3b9ae16bed5f6a599a453d253fd1ec9 1554772 tryton-sao_7.0.28+ds1.orig.tar.xz
b4223af9a507c05a3445cd5487f8eacf9af1e3327773a929599536ac44948056 39096 tryton-sao_7.0.28+ds1-1+deb13u2.debian.tar.xz
b7d3099699a4c3bf67e45fd600042ad6080951bb62501ab16e5f242d95a71771 1644600 tryton-sao_7.0.28+ds1-1+deb13u2_all.deb
741b7be29c1c385b4ff67733da56536f32c205a8819fcdfcb6feb239a138f5a1 8515 tryton-sao_7.0.28+ds1-1+deb13u2_amd64.buildinfo
Files:
a183eab7abd202daa3a69ff2277fa8e2 2101 web optional tryton-sao_7.0.28+ds1-1+deb13u2.dsc
ddb3690276861a8635eb02ce85ddd19e 1554772 web optional tryton-sao_7.0.28+ds1.orig.tar.xz
c21cccbe424869e696115441ed2b3d0e 39096 web optional tryton-sao_7.0.28+ds1-1+deb13u2.debian.tar.xz
392203b42279970eb21b34c454f1592c 1644600 web optional tryton-sao_7.0.28+ds1-1+deb13u2_all.deb
d1c2c2394c42c74b64aca8fe8b8df396 8515 web optional tryton-sao_7.0.28+ds1-1+deb13u2_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
Comment: Signed by Mathias Behrle
iQJFBAEBCgAvFiEErCl+XEa50LYccXaB1tCb5IQFu/YFAmklpYQRHG1hdGhpYXNi
QG05cy5iaXoACgkQ1tCb5IQFu/aYpw//aN/Qq91cc2EK/2VoCnJDsP4YSCqCap6i
ErZUS3hH48s48tRvvPgNiJmW5XoX1A9FHoD1RNMIf5sjbp8eH+ZZRrIFdDrOAgkU
nSNbtg0IvvtPzCq47gQiDDRDoNH8VFv++ItdFdgZcJMB81Ua3eC2vliwVoWo9rSv
R4i45ZN6GM7XEt1X0D5hvs4KmTxbpGIh9HGDPnBdDIIHhUFPsZzPsBqDIyF3+eos
ms7vs/1tnCScI5NtNPRH14nPaQsw5qNtmsv8n/xIscMS5sKZWTVy0GMSHjkXV+WJ
PiFC2DP5rwF4DKN2i8J7omHiM8l7+h21vKYS2VbY5uOCM+fXLvk1OQV3odBKKUli
W4hBXriKz43PRRpn71BQTIEvAOS7pqh67TRG9D/h+j+AZeiWpvoxJY6KGNNzqpxk
NAQUrC7VnSKzPE4sRBv7gowHJlO64u7PrxiRO06HBr0kKxi11o196ETolGdw2Zd1
nT4X28fEI+tdQKp8UBdJ4hH2b0a2dCHdB5Qs5NESgasN6TMbsDMYYYdPMfgZLcca
s467j2QlR6zaEmVSL+6HAk6ENhE+cSnuigzoNZep7geJqCWoUwyZSZ+AuXX6eLq5
Qj79ZiyXbYs9zN9VHA00FQPPS42JwDFAW06hqCDUQT4NJsJeW6iiftbBs7IRhM21
1Ju5SsAjKXo=
=fGJi
-----END PGP SIGNATURE-----