CVE-2018-14866

Incorrect access control in the TransientModel framework in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated attackers to access data in transient records that they do not own by making an RPC call before garbage collection occurs.
References
Link Resource
https://github.com/odoo/odoo/issues/32509 Patch Third Party Advisory
https://github.com/odoo/odoo/issues/32509 Patch Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:odoo:odoo:9.0:*:*:*:community:*:*:*
cpe:2.3:a:odoo:odoo:9.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:odoo:odoo:10.0:*:*:*:community:*:*:*
cpe:2.3:a:odoo:odoo:10.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:odoo:odoo:11.0:*:*:*:community:*:*:*
cpe:2.3:a:odoo:odoo:11.0:*:*:*:enterprise:*:*:*

History

21 Nov 2024, 03:49

Type Values Removed Values Added
References () https://github.com/odoo/odoo/issues/32509 - Patch, Third Party Advisory () https://github.com/odoo/odoo/issues/32509 - Patch, Third Party Advisory

Information

Published : 2019-07-03 18:15

Updated : 2024-11-21 03:49


NVD link : CVE-2018-14866

Mitre link : CVE-2018-14866

CVE.ORG link : CVE-2018-14866


JSON object : View

Products Affected

odoo

  • odoo
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource