First published: Fri Jun 28 2019(Updated: )
Improper Host header sanitization in the dbfilter routing component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows a remote attacker to deny access to the service and to disclose database names via a crafted request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Odoo Odoo | =9.0 | |
Odoo Odoo | =9.0 | |
Odoo Odoo | =10.0 | |
Odoo Odoo | =10.0 | |
Odoo Odoo | =11.0 | |
Odoo Odoo | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2018-14887.
The severity of CVE-2018-14887 is medium (6.5).
The affected software for CVE-2018-14887 is Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier.
A remote attacker can exploit CVE-2018-14887 by sending a crafted request that allows them to deny access to the service and disclose database names.
Yes, there are references available for CVE-2018-14887. You can find them at the following links: [link1](https://github.com/odoo/odoo/commits/master), [link2](https://github.com/odoo/odoo/issues/32511).