CVE-2018-14859: High severity odoo vulnerability
Incorrect access control in the password reset component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated users to reset the password of other users by being the first party to use the secure token.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-14859?
CVE-2018-14859 is a vulnerability in Odoo Community and Odoo Enterprise versions 11.0 and earlier that allows authenticated users to reset the password of other users.
What is the severity of CVE-2018-14859?
CVE-2018-14859 has a severity rating of 8.1 (high).
Which versions of Odoo are affected by CVE-2018-14859?
Versions 9.0, 10.0, and 11.0 of Odoo Community and Odoo Enterprise are affected by CVE-2018-14859.
How can authenticated users exploit CVE-2018-14859?
Authenticated users can exploit CVE-2018-14859 by being the first party to use the secure token in the password reset component.
Is there a fix for CVE-2018-14859?
Yes, a fix for CVE-2018-14859 is available. It is recommended to update to a patched version of Odoo to mitigate the vulnerability.