First published: Tue Apr 25 2023(Updated: )
A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read local files on the server, including sensitive configuration files.
Credit: security@odoo.com security@odoo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Odoo Odoo | <=15.0 | |
Odoo Odoo | <=15.0 | |
debian/odoo | 14.0.0+dfsg.2-7+deb11u1 16.0.0+dfsg.2-1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Odoo issue is CVE-2021-44476.
The severity of CVE-2021-44476 is high with a CVSS score of 6.8.
Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier are affected by CVE-2021-44476.
Authenticated administrators can exploit CVE-2021-44476 to read local files on the server, including sensitive configuration files.
Yes, there are fixes available. Please refer to the reference links for more information.