CVE-2021-44476: High severity odoo vulnerability
Published Apr 25, 2023
·Updated
A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read local files on the server, including sensitive configuration files.
Affected Software
3 affected componentsFixes available
debian/odoo
14.0.0+dfsg.2-7+deb11u116.0.0+dfsg.2-1.1
Odoo<=15.0
Odoo<=15.0
Remediation
Patch Available
Event History
Apr 25, 2023
CVE Published
via MITRE·06:33 PM
Data Sourced
via MITRE·06:33 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Odoo issue?
The vulnerability ID for this Odoo issue is CVE-2021-44476.
2
What is the severity of CVE-2021-44476?
The severity of CVE-2021-44476 is high with a CVSS score of 6.8.
3
What is affected by CVE-2021-44476?
Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier are affected by CVE-2021-44476.
4
How can authenticated administrators exploit CVE-2021-44476?
Authenticated administrators can exploit CVE-2021-44476 to read local files on the server, including sensitive configuration files.
5
Are there any fixes or patches available for CVE-2021-44476?
Yes, there are fixes available. Please refer to the reference links for more information.