PT-2023-12547 · Odoo+1 · Odoo Community+2
Swapnesh Shah
·
Publicado
2021-01-15
·
Atualizado
2024-07-15
·
CVE-2021-44465
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Odoo Community versions 13.0 and earlier
Odoo Enterprise versions 13.0 and earlier
Description
The issue allows authenticated attackers to subscribe to receive future notifications and comments related to arbitrary business records in the system via crafted RPC requests. This is due to improper access control in the affected versions of Odoo Community and Odoo Enterprise.
Recommendations
For Odoo Community versions 13.0 and earlier, update to a version later than 13.0 to resolve the issue.
For Odoo Enterprise versions 13.0 and earlier, update to a version later than 13.0 to resolve the issue.
As a temporary workaround, consider restricting access to crafted RPC requests until a patch is available.
Correção
Incorrect Authorization
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Odoo Community
Odoo Enterprise