CVE-2019-11780: High severity odoo vulnerability
Published Dec 19, 2019
·Updated
Improper access control in the computed fields system of the framework of Odoo Community 13.0 and Odoo Enterprise 13.0 allows remote authenticated attackers to access sensitive information via crafted RPC requests, which could lead to privilege escalation.
Affected Software
2 affected components
Odoo=13.0
Odoo=13.0
Remediation
Patch Available
Event History
Dec 19, 2019
CVE Published
via MITRE·03:50 PM
Data Sourced
via MITRE·03:50 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-11780.
2
What is the severity of CVE-2019-11780?
The severity of CVE-2019-11780 is high with a severity value of 8.1.
3
What is affected by CVE-2019-11780?
Odoo Community 13.0 and Odoo Enterprise 13.0 are affected by CVE-2019-11780.
4
How does CVE-2019-11780 allow attackers to access sensitive information?
CVE-2019-11780 allows remote authenticated attackers to access sensitive information via crafted RPC requests.
5
Is privilege escalation possible with CVE-2019-11780?
Yes, privilege escalation is possible with CVE-2019-11780.