PT-2023-12547 · Odoo+1 · Odoo Community+2
Swapnesh Shah
·
Published
2021-01-15
·
Updated
2024-07-15
·
CVE-2021-44465
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Odoo Community versions 13.0 and earlier
Odoo Enterprise versions 13.0 and earlier
Description
The issue allows authenticated attackers to subscribe to receive future notifications and comments related to arbitrary business records in the system via crafted RPC requests. This is due to improper access control in the affected versions of Odoo Community and Odoo Enterprise.
Recommendations
For Odoo Community versions 13.0 and earlier, update to a version later than 13.0 to resolve the issue.
For Odoo Enterprise versions 13.0 and earlier, update to a version later than 13.0 to resolve the issue.
As a temporary workaround, consider restricting access to crafted RPC requests until a patch is available.
Fix
Incorrect Authorization
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Odoo Community
Odoo Enterprise