CVE Vulnerabilities

CVE-2021-44476

Privilege Defined With Unsafe Actions

Published: Apr 25, 2023 | Modified: Nov 21, 2024
CVSS 3.x
6.8
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read local files on the server, including sensitive configuration files.

Weakness

A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.

Affected Software

NameVendorStart VersionEnd Version
OdooOdoo*15.0 (including)
OdooUbuntukinetic*
OdooUbuntulunar*
OdooUbuntumantic*
OdooUbuntuoracular*
OdooUbuntuplucky*
OdooUbuntutrusty*
OdooUbuntuxenial*

Potential Mitigations

References