PT-2019-9059 · Odoo+1 · Odoo Community+2
Nils Hamerlinck
+1
·
Published
2019-04-26
·
Updated
2020-08-24
·
CVE-2018-14861
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Odoo Community versions 10.0 through 11.0
Odoo Enterprise versions 10.0 through 11.0
Description
The issue is related to improper data access control, allowing authenticated users to export secure hashed passwords of other users via a CSV export.
Recommendations
For Odoo Community versions 10.0 through 11.0, update to a version that includes the necessary access control fixes to prevent unauthorized data exports.
For Odoo Enterprise versions 10.0 through 11.0, apply the security patch that addresses the improper data access control to restrict authenticated users from accessing sensitive user data.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Odoo Community
Odoo Enterprise