First published: Tue Apr 25 2023(Updated: )
A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read and write local files on the server.
Credit: security@odoo.com security@odoo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Odoo Odoo | <=15.0 | |
Odoo Odoo | <=15.0 | |
debian/odoo | 14.0.0+dfsg.2-7+deb11u1 16.0.0+dfsg.2-1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-23166.
The severity of CVE-2021-23166 is high, with a severity value of 8.7.
The affected software for CVE-2021-23166 includes Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier.
CVE-2021-23166 allows authenticated administrators to read and write local files on the server.
To fix CVE-2021-23166, it is recommended to update to a patched version of Odoo, such as version 14.0.0+dfsg.2-7+deb11u1 or 16.0.0+dfsg.2-1.1.