First published: Tue Jul 04 2017(Updated: )
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymization data in the Database Anonymization module allows remote authenticated privileged users to execute arbitrary Python code, because unpickle is used.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Odoo Odoo | =8.0 | |
Odoo Odoo | =9.0 | |
Odoo Odoo | =9.0 | |
Odoo Odoo | =10.0 | |
Odoo Odoo | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-10803 is considered to be of high severity due to the potential for remote code execution.
To fix CVE-2017-10803, it is recommended to upgrade Odoo to a version that does not use unpickle in the Database Anonymization module.
CVE-2017-10803 affects users of Odoo versions 8.0, 9.0, and 10.0, both Community and Enterprise Editions.
No, exploitation of CVE-2017-10803 requires remote authenticated privileged user access.
The potential consequences of CVE-2017-10803 include arbitrary code execution, which can compromise the security of the system.