CVE-2021-23178: High severity odoo vulnerability
Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments with a tokenized payment method that belongs to another user, causing the victim's payment method to be charged instead.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-23178?
CVE-2021-23178 is a vulnerability in Odoo Community and Odoo Enterprise that allows attackers to validate online payments with a tokenized payment method that belongs to another user, causing the victim's payment method to be charged instead.
How severe is CVE-2021-23178?
CVE-2021-23178 has a severity rating of 7.5 (high).
Which versions of Odoo are affected by CVE-2021-23178?
CVE-2021-23178 affects Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier.
How can I fix CVE-2021-23178?
To fix CVE-2021-23178, it is recommended to upgrade to Odoo version 16.0.0+dfsg.2-1.1 or apply the patch provided by Odoo.
Where can I find more information about CVE-2021-23178?
You can find more information about CVE-2021-23178 on the Odoo GitHub page (https://github.com/odoo/odoo/issues/107690) and the Debian Security Advisory (https://www.debian.org/security/2023/dsa-5399).