CVE-2021-45111: High severity odoo vulnerability
Published Apr 25, 2023
·Updated
Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to trigger the creation of demonstration data, including user accounts with known credentials.
Affected Software
3 affected componentsFixes available
debian/odoo
14.0.0+dfsg.2-7+deb11u116.0.0+dfsg.2-1.1
Odoo<=15.0
Odoo<=15.0
Remediation
Patch Available
Event History
Apr 25, 2023
CVE Published
via MITRE·06:33 PM
Data Sourced
via MITRE·06:33 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this security issue in Odoo?
The vulnerability ID of this security issue in Odoo is CVE-2021-45111.
2
What is the severity of CVE-2021-45111?
The severity of CVE-2021-45111 is high with a CVSS score of 8.1.
3
What is affected by CVE-2021-45111?
Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier are affected by CVE-2021-45111.
4
How can remote authenticated users exploit CVE-2021-45111?
Remote authenticated users can exploit CVE-2021-45111 to trigger the creation of demonstration data, including user accounts with known credentials.
5
How can I fix CVE-2021-45111 in Odoo?
To fix CVE-2021-45111 in Odoo, update to version 14.0.0+dfsg.2-7+deb11u1 or version 16.0.0+dfsg.2-1.1.