First published: Tue Apr 25 2023(Updated: )
Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to trigger the creation of demonstration data, including user accounts with known credentials.
Credit: security@odoo.com security@odoo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Odoo Odoo | <=15.0 | |
Odoo Odoo | <=15.0 | |
debian/odoo | 14.0.0+dfsg.2-7+deb11u1 16.0.0+dfsg.2-1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this security issue in Odoo is CVE-2021-45111.
The severity of CVE-2021-45111 is high with a CVSS score of 8.1.
Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier are affected by CVE-2021-45111.
Remote authenticated users can exploit CVE-2021-45111 to trigger the creation of demonstration data, including user accounts with known credentials.
To fix CVE-2021-45111 in Odoo, update to version 14.0.0+dfsg.2-7+deb11u1 or version 16.0.0+dfsg.2-1.1.