CVE-2021-44460: High severity odoo vulnerability
Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows users with deactivated accounts to access the system with the deactivated account and any permission it still holds, via crafted RPC requests.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID is CVE-2021-44460.
What is the severity level of CVE-2021-44460?
The severity level of CVE-2021-44460 is high with a score of 6.5.
Which versions of Odoo Community and Odoo Enterprise are affected by CVE-2021-44460?
Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier are affected by CVE-2021-44460.
How does CVE-2021-44460 impact the system?
CVE-2021-44460 allows users with deactivated accounts to access the system with the deactivated account and any permission it still holds, via crafted RPC requests.
Is there a fix available for CVE-2021-44460?
As of now, there is no official fix available for CVE-2021-44460. It is recommended to update to a newer version when a patch or update is released by Odoo.