Security Release for issue #13142
Briefly

Cédric Krier has found that trytond accepts compressed content from unauthenticated requests which makes it vulnerable to zip bomb attacks.
A proxy can be deployed in front of the trytond server to forbid this kind of request.
All affected users should upgrade trytond to the latest version.
Any security concerns should be reported on the bug-tracker at https://bugs.tryton.org/ with the confidential checkbox checked.
Read at Tryton Discussion
[
add
]
[
|
|
]