CVE-2018-14887: Input Validation
Improper Host header sanitization in the dbfilter routing component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows a remote attacker to deny access to the service and to disclose database names via a crafted request.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-14887.
What is the severity of CVE-2018-14887?
The severity of CVE-2018-14887 is medium (6.5).
What is the affected software for CVE-2018-14887?
The affected software for CVE-2018-14887 is Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier.
How can a remote attacker exploit CVE-2018-14887?
A remote attacker can exploit CVE-2018-14887 by sending a crafted request that allows them to deny access to the service and disclose database names.
Are there any references for CVE-2018-14887?
Yes, there are references available for CVE-2018-14887. You can find them at the following links: [link1](https://github.com/odoo/odoo/commits/master), [link2](https://github.com/odoo/odoo/issues/32511).