PT-2023-12547 · Odoo+1 · Odoo Community+2

Swapnesh Shah

·

Publicado

2021-01-15

·

Atualizado

2024-07-15

·

CVE-2021-44465

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Odoo Community versions 13.0 and earlier Odoo Enterprise versions 13.0 and earlier
Description The issue allows authenticated attackers to subscribe to receive future notifications and comments related to arbitrary business records in the system via crafted RPC requests. This is due to improper access control in the affected versions of Odoo Community and Odoo Enterprise.
Recommendations For Odoo Community versions 13.0 and earlier, update to a version later than 13.0 to resolve the issue. For Odoo Enterprise versions 13.0 and earlier, update to a version later than 13.0 to resolve the issue. As a temporary workaround, consider restricting access to crafted RPC requests until a patch is available.

Correção

Incorrect Authorization

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2021-1048
ALT-PU-2021-1236
BIT-ODOO-2021-44465
CVE-2021-44465

Produtos afetados

Alt Linux
Odoo Community
Odoo Enterprise