PT-2019-9059 · Odoo+1 · Odoo Community+2

Nils Hamerlinck

+1

·

Published

2019-04-26

·

Updated

2020-08-24

·

CVE-2018-14861

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Odoo Community versions 10.0 through 11.0 Odoo Enterprise versions 10.0 through 11.0
Description The issue is related to improper data access control, allowing authenticated users to export secure hashed passwords of other users via a CSV export.
Recommendations For Odoo Community versions 10.0 through 11.0, update to a version that includes the necessary access control fixes to prevent unauthorized data exports. For Odoo Enterprise versions 10.0 through 11.0, apply the security patch that addresses the improper data access control to restrict authenticated users from accessing sensitive user data.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1740
CVE-2018-14861

Affected Products

Alt Linux
Odoo Community
Odoo Enterprise