CVE-2021-23166: High severity odoo vulnerability
Published Apr 25, 2023
·Updated
A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read and write local files on the server.
Affected Software
3 affected componentsFixes available
debian/odoo
14.0.0+dfsg.2-7+deb11u116.0.0+dfsg.2-1.1
Odoo<=15.0
Odoo<=15.0
Remediation
Patch Available
Event History
Apr 25, 2023
CVE Published
via MITRE·06:33 PM
Data Sourced
via MITRE·06:33 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-23166.
2
What is the severity of CVE-2021-23166?
The severity of CVE-2021-23166 is high, with a severity value of 8.7.
3
What is the affected software for CVE-2021-23166?
The affected software for CVE-2021-23166 includes Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier.
4
How does CVE-2021-23166 impact the system?
CVE-2021-23166 allows authenticated administrators to read and write local files on the server.
5
How can I fix CVE-2021-23166?
To fix CVE-2021-23166, it is recommended to update to a patched version of Odoo, such as version 14.0.0+dfsg.2-7+deb11u1 or 16.0.0+dfsg.2-1.1.