PT-2020-8542 · Odoo+1 · Odoo Community+2

Nils Hamerlinck

·

Published

2020-12-22

·

Updated

2021-02-08

·

CVE-2018-15645

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Odoo Community versions 12.0 and earlier Odoo Enterprise versions 12.0 and earlier
Description: The issue is related to improper access control in message routing, allowing remote authenticated users to create arbitrary records via crafted payloads. This may lead to privilege escalation.
Recommendations: For Odoo Community versions 12.0 and earlier, update to a version that includes the necessary security patches to fix the improper access control issue. For Odoo Enterprise versions 12.0 and earlier, update to a version that includes the necessary security patches to fix the improper access control issue. As a temporary workaround, consider restricting access to the message routing functionality to minimize the risk of exploitation.

Fix

Improper Access Control

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1048
ALT-PU-2021-1236
CVE-2018-15645

Affected Products

Alt Linux
Odoo Community
Odoo Enterprise