First published: Tue Feb 25 2025(Updated: )
Improper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user to export the OAuth tokens of other users.
Credit: security@odoo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Odoo Community | ||
Odoo Enterprise | ||
=15.0 | ||
=15.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-12368 is classified as a high severity vulnerability due to its potential to expose sensitive OAuth tokens.
To mitigate CVE-2024-12368, update to the latest patched version of Odoo Community or Odoo Enterprise that addresses the access control issue.
CVE-2024-12368 affects internal users of Odoo Community 15.0 and Odoo Enterprise 15.0 with improper access control in the auth_oauth module.
CVE-2024-12368 is caused by improper access control settings that allow users to export OAuth tokens belonging to other users.
The impact of CVE-2024-12368 includes potential unauthorized access to OAuth tokens, which could lead to further data breaches.