Skip to Content
Odoo Menú
  • Registra entrada
  • Prova-ho gratis
  • Aplicacions
    Finances
    • Comptabilitat
    • Facturació
    • Despeses
    • Full de càlcul (IA)
    • Documents
    • Signatura
    Vendes
    • CRM
    • Vendes
    • Punt de venda per a botigues
    • Punt de venda per a restaurants
    • Subscripcions
    • Lloguer
    Imatges de llocs web
    • Creació de llocs web
    • Comerç electrònic
    • Blog
    • Fòrum
    • Xat en directe
    • Aprenentatge en línia
    Cadena de subministrament
    • Inventari
    • Fabricació
    • PLM
    • Compres
    • Manteniment
    • Qualitat
    Recursos humans
    • Empleats
    • Reclutament
    • Absències
    • Avaluacions
    • Recomanacions
    • Flota
    Màrqueting
    • Màrqueting Social
    • Màrqueting per correu electrònic
    • Màrqueting per SMS
    • Esdeveniments
    • Automatització del màrqueting
    • Enquestes
    Serveis
    • Projectes
    • Fulls d'hores
    • Servei de camp
    • Suport
    • Planificació
    • Cites
    Productivitat
    • Converses
    • Validacions
    • IoT
    • VoIP
    • Coneixements
    • WhatsApp
    Aplicacions de tercers Odoo Studio Plataforma d'Odoo al núvol
  • Sectors
    Comerç al detall
    • Llibreria
    • Botiga de roba
    • Botiga de mobles
    • Botiga d'ultramarins
    • Ferreteria
    • Botiga de joguines
    Food & Hospitality
    • Bar i pub
    • Restaurant
    • Menjar ràpid
    • Guest House
    • Distribuïdor de begudes
    • Hotel
    Immobiliari
    • Agència immobiliària
    • Estudi d'arquitectura
    • Construcció
    • Gestió immobiliària
    • Jardineria
    • Associació de propietaris de béns immobles
    Consultoria
    • Empresa comptable
    • Partner d'Odoo
    • Agència de màrqueting
    • Bufet d'advocats
    • Captació de talent
    • Auditoria i certificació
    Fabricació
    • Textile
    • Metal
    • Mobles
    • Menjar
    • Brewery
    • Regals corporatius
    Salut i fitness
    • Club d'esport
    • Òptica
    • Centre de fitness
    • Especialistes en benestar
    • Farmàcia
    • Perruqueria
    Trades
    • Servei de manteniment
    • Hardware i suport informàtic
    • Sistemes d'energia solar
    • Shoe Maker
    • Serveis de neteja
    • Instal·lacions HVAC
    Altres
    • Nonprofit Organization
    • Agència del medi ambient
    • Lloguer de panells publicitaris
    • Fotografia
    • Lloguer de bicicletes
    • Distribuïdors de programari
    Browse all Industries
  • Comunitat
    Aprèn
    • Tutorials
    • Documentació
    • Certificacions
    • Formació
    • Blog
    • Pòdcast
    Potenciar l'educació
    • Programa educatiu
    • Scale-Up! El joc empresarial
    • Visita Odoo
    Obtindre el programari
    • Descarregar
    • Comparar edicions
    • Novetats de les versions
    Col·laborar
    • GitHub
    • Fòrum
    • Esdeveniments
    • Traduccions
    • Converteix-te en partner
    • Services for Partners
    • Registra la teva empresa comptable
    Obtindre els serveis
    • Troba un partner
    • Troba un comptable
    • Contacta amb un expert
    • Serveis d'implementació
    • Referències del client
    • Suport
    • Actualitzacions
    Github Youtube Twitter Linkedin Instagram Facebook Spotify
    +1 (650) 691-3277
    Programar una demo
  • Preus
  • Ajuda
  1. Llistes de correu
  2. Announcements
  3. Odoo Security Advisories - ODOO-SA-2018-11-28 | ODOO-SA-2018-08-07

Arxius

  • Per fil 36
  • Per data
    • de desembre 2017 7
    • de febrer 2018 1
    • de març 2018 1
    • d’abril 2018 14
    • de maig 2018 5
    • de juny 2018 8
    • de juliol 2018 6
    • d’agost 2018 2
    • de novembre 2018 2
    • de gener 2019 2
    • de març 2019 1
    • d’abril 2019 1
    • d’octubre 2019 1
    • de desembre 2019 1
    • de gener 2020 1
    • de juliol 2020 3
    • d’agost 2020 1
    • de desembre 2020 1
    • de juny 2022 1
    • de setembre 2022 1
    • d’octubre 2022 1

Announcements

announcements@mail.odoo.com

Odoo Community & Enterprise

Odoo Security Advisory disclosure: ODOO-SA-2019-10-25

Odoo Security Advisories - ODOO-SA-2018-11-28 | ODOO-SA-2018-08-07

Several security advisories have just been disclosed, as described below.
Please be sure that your deployments are up-to-date. Follow the links at the end of the summary to read the detailed disclosure, including reference revision numbers and dates.

If you are unsure about the update process, please refer to our online instructions, valid for all versions:
  https://www.odoo.com/documentation/12.0/setup/update.html

Note: this is a notification of public disclosure of security issues from 2018 - the private disclosure already took place in 2018.
If you are using one of the Odoo Cloud-hosted services (Odoo Online | Odoo.SH) there is nothing to do, these updates were automatically applied as soon as the corrections were available.
If you have a valid Odoo Enterprise subscription, you have already been notified during the private disclosure - this only serves as a reminder.


~~~

# ODOO-SA-2018-11-28-1 (CVE-2018-15640)
  Severity :: High :: 8.1 :: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
  Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through
  12.0 allows remote authenticated attackers to obtain elevated privileges
  via a crafted request.
  https://github.com/odoo/odoo/issues/32514

# ODOO-SA-2018-11-28-2 (CVE-2018-15635)
  Severity :: Medium :: 5.9 :: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N
  Cross-site scripting vulnerability in the Discuss App of Odoo Community 12.0
  and earlier, and Odoo Enterprise 12.0 and earlier allows remote attackers to
  inject arbitrary web script in the browser of an internal user of the system
  by tricking them into inviting a follower on a document with a crafted name.
  https://github.com/odoo/odoo/issues/32515

# ODOO-SA-2018-11-28-3 (CVE-2018-15631)
  Severity :: Medium :: 6.5 :: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  Improper access control in the Discuss App of Odoo Community 12.0 and earlier
  and Odoo Enterprise 12.0 and earlier allows remote authenticated attackers to
  e-mail themselves arbitrary files from the database, via a crafted RPC
  request.
  https://github.com/odoo/odoo/issues/32516

~~~

# ODOO-SA-2018-08-07-1 (CVE-2018-14865)
  Severity: High :: 7.7
  Report engine in Odoo Community 11.0 and earlier and Odoo Enterprise
  11.0 and earlier does not use secure options when passing documents to
  wkhtmltopdf, which allows remote attackers to read local files.
  https://github.com/odoo/odoo/issues/32501

# ODOO-SA-2018-08-07-2 (CVE-2018-14864)
  Severity: Medium :: 6.3
  Incorrect access control in asset bundles in Odoo Community 11.0 and
  earlier and Odoo Enterprise 11.0 and earlier allows remote
  authenticated users to inject arbitrary web script via a crafted attachment.
  https://github.com/odoo/odoo/issues/32502

# ODOO-SA-2018-08-07-3 (CVE-2018-14867)
  Severity: Medium :: 6.5
  Incorrect access control in the portal messaging system in Odoo Community
  9.0 and 10.0 and Odoo Enterprise 9.0 and 10.0 allows remote attackers
  to post messages on behalf of customers, and to guess document
  attribute values, via crafted parameters.
  https://github.com/odoo/odoo/issues/32503

# ODOO-SA-2018-08-07-4 (CVE-2018-14862)
  Severity: High :: 7.1
  Incorrect access control in the mail templating system in Odoo Community
  11.0 and earlier and Odoo Enterprise 11.0 and earlier allows
  authenticated internal users to delete arbitrary menuitems via a crafted
  RPC request.
  https://github.com/odoo/odoo/issues/32504

# ODOO-SA-2018-08-07-5 (CVE-2018-14860)
  Severity: Critical :: 9.1
  Improper sanitization of dynamic user expressions in Odoo Community
  11.0 and earlier and Odoo Enterprise 11.0 and earlier allows
  authenticated privileged users to escape from the dynamic expression sandbox
  and execute arbitrary code on the hosting system.
  https://github.com/odoo/odoo/issues/32505

# ODOO-SA-2018-08-07-6 (CVE-2018-14861)
  Severity: Medium:: 4.3
  Improper data access control in Odoo Community 10.0 and 11.0 and Odoo
  Enterprise 10.0 and 11.0 allows authenticated users to perform a CSV export  
  of the secure hashed passwords of other users.
  https://github.com/odoo/odoo/issues/32506

# ODOO-SA-2018-08-07-7 (CVE-2018-14868)
  Severity: High:: 8.1
  Incorrect access control in the Password Encryption module in Odoo
  Community 9.0 and Odoo Enterprise 9.0 allows authenticated users to
  change the password of other users without knowing their current
  password via a crafted RPC call.
  https://github.com/odoo/odoo/issues/32507

# ODOO-SA-2018-08-07-8 (CVE-2018-14863)
  Severity: High :: 8.1
  Incorrect access control in the RPC framework in Odoo Community 8.0
  through 11.0 and Odoo Enterprise 9.0 through 11.0 allows authenticated
  users to call private functions via RPC.
  https://github.com/odoo/odoo/issues/32508

# ODOO-SA-2018-08-07-9 (CVE-2018-14866)
  Severity: Low :: 3.5
  Incorrect access control in the TransientModel framework in Odoo
  Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows
  authenticated attackers to access data in transient records that they
  do not own by making an RPC call before garbage collection occurs.
  https://github.com/odoo/odoo/issues/32509

# ODOO-SA-2018-08-07-10 (CVE-2018-14859)
  Severity: High :: 8.1
  Incorrect access control in the password reset component in Odoo
  Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows
  authenticated users to reset the password of other users by being the first
  party to use the secure token.
  https://github.com/odoo/odoo/issues/32510

# ODOO-SA-2018-08-07-11 (CVE-2018-14887)
  Severity: High :: 6.5
  Improper Host header sanitization in the dbfilter routing component in Odoo
  Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows
  a remote attacker to deny access to the service and to disclose
  database names via a crafted request.
  https://github.com/odoo/odoo/issues/32511

# ODOO-SA-2018-08-07-12 (CVE-2018-14885)
  Severity: High :: 8.2
  Incorrect access control in the database manager component in Odoo
  Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a
  remote attacker to restore a database dump without knowing the
  super-admin password. An arbitrary password succeeds.
  https://github.com/odoo/odoo/issues/32512


# ODOO-SA-2018-08-07-13 (CVE-2018-14886)
  Severity: High :: 6.8
  The module-description renderer in Odoo Community 11.0 and earlier and Odoo
  Enterprise 11.0 and earlier does not disable RST's local file
  inclusion, which allows privileged authenticated users to read local
  files via a crafted module description.
  https://github.com/odoo/odoo/issues/32513


per Olivier Dony (odo) - 10:21 - 8 d’abr. 2019
Community
  • Tutorials
  • Documentació
  • Fòrum
Codi obert
  • Descarregar
  • GitHub
  • Runbot
  • Traduccions
Serveis
  • Allotjament a Odoo.sh
  • Suport
  • Actualització
  • Desenvolupaments personalitzats
  • Educació
  • Troba un comptable
  • Troba un partner
  • Converteix-te en partner
Sobre nosaltres
  • La nostra empresa
  • Actius de marca
  • Contacta amb nosaltres
  • Llocs de treball
  • Esdeveniments
  • Pòdcast
  • Blog
  • Clients
  • Informació legal • Privacitat
  • Seguretat
الْعَرَبيّة Català 简体中文 繁體中文 (台灣) Čeština Dansk Nederlands English Suomi Français Deutsch हिंदी Bahasa Indonesia Italiano 日本語 한국어 (KR) Lietuvių kalba Język polski Português (BR) română русский язык Slovenský jazyk slovenščina Español (América Latina) Español ภาษาไทย Türkçe українська Tiếng Việt

Odoo és un conjunt d'aplicacions empresarials de codi obert que cobreix totes les necessitats de la teva empresa: CRM, comerç electrònic, comptabilitat, inventari, punt de venda, gestió de projectes, etc.

La proposta única de valor d'Odoo és ser molt fàcil d'utilitzar i estar totalment integrat, ambdues alhora.

Website made with

Odoo Experience on YouTube

1. Use the live chat to ask your questions.
2. The operator answers within a few minutes.

Live support on Youtube
Watch now