CVE-2018-14866: Medium severity odoo vulnerability
Incorrect access control in the TransientModel framework in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated attackers to access data in transient records that they do not own by making an RPC call before garbage collection occurs.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-14866.
What is the affected software for this vulnerability?
The affected software for this vulnerability is Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier.
What is the severity of CVE-2018-14866?
The severity of CVE-2018-14866 is medium with a severity value of 4.3.
How do authenticated attackers exploit CVE-2018-14866?
Authenticated attackers exploit CVE-2018-14866 by making an RPC call before garbage collection occurs to access data in transient records that they do not own.
Is there a fix available for this vulnerability?
Yes, a fix is available for this vulnerability. It is recommended to update to a version that is not affected by the vulnerability.