PT-2019-9059 · Odoo+1 · Odoo Community+2
Nils Hamerlinck
+1
·
Publicado
2019-04-26
·
Atualizado
2020-08-24
·
CVE-2018-14861
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Odoo Community versions 10.0 through 11.0
Odoo Enterprise versions 10.0 through 11.0
Description
The issue is related to improper data access control, allowing authenticated users to export secure hashed passwords of other users via a CSV export.
Recommendations
For Odoo Community versions 10.0 through 11.0, update to a version that includes the necessary access control fixes to prevent unauthorized data exports.
For Odoo Enterprise versions 10.0 through 11.0, apply the security patch that addresses the improper data access control to restrict authenticated users from accessing sensitive user data.
Correção
Incorrect Permission
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Odoo Community
Odoo Enterprise