PT-2019-9070 · Odoo+1 · Odoo Community+2

Stephane Bidoul

·

Published

2019-04-26

·

Updated

2020-08-24

·

CVE-2018-14886

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Odoo Community versions 11.0 and earlier Odoo Enterprise versions 11.0 and earlier
Description The issue concerns the module-description renderer, which fails to disable RST's local file inclusion. This allows privileged authenticated users to read local files by crafting a module description.
Recommendations For Odoo Community versions 11.0 and earlier, update to a version that fixes this issue. For Odoo Enterprise versions 11.0 and earlier, update to a version that fixes this issue. As a temporary workaround, consider restricting access to the module-description renderer to minimize the risk of exploitation.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1740
CVE-2018-14886

Affected Products

Alt Linux
Odoo Community
Odoo Enterprise