CVE-2018-14733: Input Validation
Published Jul 5, 2019
·Updated
The Odoo Community Association (OCA) dbfilterfromheader module makes Odoo 8.x, 9.x, 10.x, and 11.x vulnerable to ReDoS (regular expression denial of service) under certain circumstances.
Affected Software
8 affected components
Odoo=8.0
Odoo=8.0
Odoo=9.0
Odoo=9.0
Odoo=10.0
Odoo=10.0
Odoo=11.0
Odoo=11.0
Event History
Jul 5, 2019
CVE Published
via MITRE·07:54 PM
Data Sourced
via MITRE·07:54 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2018-14733.
2
What is the severity of CVE-2018-14733?
The severity of CVE-2018-14733 is high with a CVSS score of 7.5.
3
Which versions of Odoo are affected by CVE-2018-14733?
Odoo versions 8.x, 9.x, 10.x, and 11.x are affected by CVE-2018-14733.
4
What is the vulnerability of CVE-2018-14733?
CVE-2018-14733 is a ReDoS (regular expression denial of service) vulnerability.
5
How can I fix CVE-2018-14733?
To fix CVE-2018-14733, update the OCA dbfilter_from_header module to the latest version.