CVE-2017-9416: Path Traversal
Published Jun 3, 2017
·Updated
Directory traversal vulnerability in tools.fileopen in Odoo 8.0, 9.0, and 10.0 allows remote authenticated users to read arbitrary local files readable by the Odoo service.
Affected Software
3 affected components
Odoo=8.0
Odoo=9.0
Odoo=10.0
Remediation
Patch Available
Event History
Jun 3, 2017
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9416?
CVE-2017-9416 is classified as a medium severity vulnerability due to its potential to allow unauthorized file access.
2
How do I fix CVE-2017-9416?
To fix CVE-2017-9416, you should upgrade Odoo to a version that is not vulnerable, such as the latest releases beyond 10.0.
3
What systems are affected by CVE-2017-9416?
CVE-2017-9416 affects Odoo versions 8.0, 9.0, and 10.0.
4
What types of attacks can exploit CVE-2017-9416?
CVE-2017-9416 can be exploited by remote authenticated users to read arbitrary local files on the server.
5
Is there a workaround for CVE-2017-9416?
A potential workaround for CVE-2017-9416 is to limit user access and restrict file permissions on the server.