First published: Sun Jun 04 2017(Updated: )
Directory traversal vulnerability in tools.file_open in Odoo 8.0, 9.0, and 10.0 allows remote authenticated users to read arbitrary local files readable by the Odoo service.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Odoo Odoo | =8.0 | |
Odoo Odoo | =9.0 | |
Odoo Odoo | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9416 is classified as a medium severity vulnerability due to its potential to allow unauthorized file access.
To fix CVE-2017-9416, you should upgrade Odoo to a version that is not vulnerable, such as the latest releases beyond 10.0.
CVE-2017-9416 affects Odoo versions 8.0, 9.0, and 10.0.
CVE-2017-9416 can be exploited by remote authenticated users to read arbitrary local files on the server.
A potential workaround for CVE-2017-9416 is to limit user access and restrict file permissions on the server.