PT-2023-12547 · Odoo+1 · Odoo Community+2

Swapnesh Shah

·

Published

2021-01-15

·

Updated

2024-07-15

·

CVE-2021-44465

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Odoo Community versions 13.0 and earlier Odoo Enterprise versions 13.0 and earlier
Description The issue allows authenticated attackers to subscribe to receive future notifications and comments related to arbitrary business records in the system via crafted RPC requests. This is due to improper access control in the affected versions of Odoo Community and Odoo Enterprise.
Recommendations For Odoo Community versions 13.0 and earlier, update to a version later than 13.0 to resolve the issue. For Odoo Enterprise versions 13.0 and earlier, update to a version later than 13.0 to resolve the issue. As a temporary workaround, consider restricting access to crafted RPC requests until a patch is available.

Fix

Incorrect Authorization

Improper Access Control

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1048
ALT-PU-2021-1236
BIT-ODOO-2021-44465
CVE-2021-44465

Affected Products

Alt Linux
Odoo Community
Odoo Enterprise