Skip to Content
Menu
This question has been flagged
2 Replies
2119 Views

Hello,

odoo keeps a record of entries in the system with the password in plain text.

It is stored in the datatir in forlder /sesions

Isn't it a vulnerability?

How can I avoid it?

Is it ready a module to solve this?

Thanks.


Avatar
Discard

tell me the path where passwords are stored in clear form? as far as I know, passwords are stored in the database in the form of hashes with salt

Author Best Answer

/odoo/.local/share/Odoo/sessions

Avatar
Discard

Yes, it's true, vulnerability

Hi

no, this is the default module and it encrypts passwords in the database, and the above describes the vulnerability in the session data are different things