Sandboxing Vulnerability in Odoo by Odoo S.A.
CVE-2021-23166

8.7HIGH

Key Information:

Vendor

Odoo

Vendor
CVE Published:
25 April 2023

What is CVE-2021-23166?

A sandboxing vulnerability present in Odoo Community and Enterprise versions up to 15.0 allows authenticated administrators to bypass file access restrictions. This could lead to unauthorized reading and writing of local files on the server, potentially compromising sensitive data. It is crucial for administrators to apply relevant patches and updates to mitigate this risk and secure their systems. For further details, refer to the Odoo GitHub issue and the Debian security advisory.

Affected Version(s)

Odoo Community 0 <= 15.0

Odoo Enterprise 0 <= 15.0

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nils Hamerlinck
.