CVE-2019-11780

Improper access control in the computed fields system of the framework of Odoo Community 13.0 and Odoo Enterprise 13.0 allows remote authenticated attackers to access sensitive information via crafted RPC requests, which could lead to privilege escalation.
References
Link Resource
https://github.com/odoo/odoo/issues/42196 Patch Third Party Advisory
https://github.com/odoo/odoo/issues/42196 Patch Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:odoo:odoo:13.0:*:*:*:community:*:*:*
cpe:2.3:a:odoo:odoo:13.0:*:*:*:enterprise:*:*:*

History

21 Nov 2024, 04:21

Type Values Removed Values Added
References () https://github.com/odoo/odoo/issues/42196 - Patch, Third Party Advisory () https://github.com/odoo/odoo/issues/42196 - Patch, Third Party Advisory

Information

Published : 2019-12-19 16:16

Updated : 2024-11-21 04:21


NVD link : CVE-2019-11780

Mitre link : CVE-2019-11780

CVE.ORG link : CVE-2019-11780


JSON object : View

Products Affected

odoo

  • odoo
CWE
CWE-284

Improper Access Control

NVD-CWE-Other