First published: Tue Dec 22 2020(Updated: )
A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3.6 or later, allows remote authenticated users to execute arbitrary code, leading to privilege escalation.
Credit: security@odoo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Odoo Odoo | >=11.0<=13.0 | |
Odoo Odoo | >=11.0<=13.0 | |
Python Python | >=3.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-29396 is a sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0 that allows remote authenticated users to execute arbitrary code, leading to privilege escalation.
CVE-2020-29396 has a severity rating of 8.8 out of 10 (critical).
Odoo Community versions 11.0 through 13.0 and Odoo Enterprise versions 11.0 through 13.0 are affected by CVE-2020-29396.
Remote authenticated users can exploit CVE-2020-29396 to execute arbitrary code, which can lead to privilege escalation.
No, Python versions after 3.6.0 are not vulnerable to CVE-2020-29396.