CVE-2017-5871: Medium severity Odoo vulnerability
Published May 22, 2019
·Updated
Odoo Version <= 8.0-20160726 and Version 9 is affected by: CWE-601: Open redirection. The impact is: obtain sensitive information (remote).
Affected Software
4 affected components
Odoo=8.0
Odoo=8.0-20160726
Odoo=9.0
Odoo=10.0
Event History
May 22, 2019
CVE Published
via MITRE·07:33 PM
Data Sourced
via MITRE·07:33 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Odoo vulnerability?
The vulnerability ID for this Odoo vulnerability is CVE-2017-5871.
2
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-601.
3
What is the impact of this vulnerability?
The impact of this vulnerability is obtaining sensitive information remotely.
4
How does this vulnerability affect Odoo versions?
This vulnerability affects Odoo versions <= 8.0-20160726 and version 9, and Odoo version 10.0 is not affected.
5
How severe is this vulnerability?
This vulnerability has a severity rating of medium (CVSS score: 5.4).
6
How can I fix this vulnerability?
To fix this vulnerability, update your Odoo installation to a version that is not affected by the vulnerability.