CVE-2017-10803: High severity odoo vulnerability
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymization data in the Database Anonymization module allows remote authenticated privileged users to execute arbitrary Python code, because unpickle is used.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-10803?
CVE-2017-10803 is considered to be of high severity due to the potential for remote code execution.
How do I fix CVE-2017-10803?
To fix CVE-2017-10803, it is recommended to upgrade Odoo to a version that does not use unpickle in the Database Anonymization module.
Who is affected by CVE-2017-10803?
CVE-2017-10803 affects users of Odoo versions 8.0, 9.0, and 10.0, both Community and Enterprise Editions.
Can CVE-2017-10803 be exploited without authentication?
No, exploitation of CVE-2017-10803 requires remote authenticated privileged user access.
What are the potential consequences of CVE-2017-10803?
The potential consequences of CVE-2017-10803 include arbitrary code execution, which can compromise the security of the system.