PT-2020-8542 · Odoo+1 · Odoo Community+2
Nils Hamerlinck
·
Published
2020-12-22
·
Updated
2021-02-08
·
CVE-2018-15645
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Odoo Community versions 12.0 and earlier
Odoo Enterprise versions 12.0 and earlier
Description:
The issue is related to improper access control in message routing, allowing remote authenticated users to create arbitrary records via crafted payloads. This may lead to privilege escalation.
Recommendations:
For Odoo Community versions 12.0 and earlier, update to a version that includes the necessary security patches to fix the improper access control issue.
For Odoo Enterprise versions 12.0 and earlier, update to a version that includes the necessary security patches to fix the improper access control issue.
As a temporary workaround, consider restricting access to the message routing functionality to minimize the risk of exploitation.
Fix
Improper Access Control
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Odoo Community
Odoo Enterprise