CVE-2024-12368: High severity odoo community vulnerability
Improper access control in the authoauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user to export the OAuth tokens of other users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12368?
CVE-2024-12368 is classified as a high severity vulnerability due to its potential to expose sensitive OAuth tokens.
How do I fix CVE-2024-12368?
To mitigate CVE-2024-12368, update to the latest patched version of Odoo Community or Odoo Enterprise that addresses the access control issue.
Who is affected by CVE-2024-12368?
CVE-2024-12368 affects internal users of Odoo Community 15.0 and Odoo Enterprise 15.0 with improper access control in the auth_oauth module.
What causes CVE-2024-12368?
CVE-2024-12368 is caused by improper access control settings that allow users to export OAuth tokens belonging to other users.
What is the impact of CVE-2024-12368?
The impact of CVE-2024-12368 includes potential unauthorized access to OAuth tokens, which could lead to further data breaches.