CVE Vulnerabilities

CVE-2021-44547

Privilege Defined With Unsafe Actions

Published: Apr 25, 2023 | Modified: Nov 21, 2024
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

A sandboxing issue in Odoo Community 15.0 and Odoo Enterprise 15.0 allows authenticated administrators to executed arbitrary code, leading to privilege escalation.

Weakness

A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.

Affected Software

Name Vendor Start Version End Version
Odoo Odoo * 15.0 (including)
Odoo Ubuntu kinetic *
Odoo Ubuntu lunar *
Odoo Ubuntu mantic *
Odoo Ubuntu trusty *
Odoo Ubuntu xenial *

Potential Mitigations

References