Skip to Content
Odoo Menu
  • Sign in
  • Try it free
  • Apps
    Finance
    • Accounting
    • Invoicing
    • Expenses
    • Spreadsheet (BI)
    • Documents
    • Sign
    Sales
    • CRM
    • Sales
    • POS Shop
    • POS Restaurant
    • Subscriptions
    • Rental
    Websites
    • Website Builder
    • eCommerce
    • Blog
    • Forum
    • Live Chat
    • eLearning
    Supply Chain
    • Inventory
    • Manufacturing
    • PLM
    • Purchase
    • Maintenance
    • Quality
    Human Resources
    • Employees
    • Recruitment
    • Time Off
    • Appraisals
    • Referrals
    • Fleet
    Marketing
    • Social Marketing
    • Email Marketing
    • SMS Marketing
    • Events
    • Marketing Automation
    • Surveys
    Services
    • Project
    • Timesheets
    • Field Service
    • Helpdesk
    • Planning
    • Appointments
    Productivity
    • Discuss
    • Approvals
    • IoT
    • VoIP
    • Knowledge
    • WhatsApp
    Third party apps Odoo Studio Odoo Cloud Platform
  • Industries
    Retail
    • Book Store
    • Clothing Store
    • Furniture Store
    • Grocery Store
    • Hardware Store
    • Toy Store
    Food & Hospitality
    • Bar and Pub
    • Restaurant
    • Fast Food
    • Guest House
    • Beverage Distributor
    • Hotel
    Real Estate
    • Real Estate Agency
    • Architecture Firm
    • Construction
    • Estate Management
    • Gardening
    • Property Owner Association
    Consulting
    • Accounting Firm
    • Odoo Partner
    • Marketing Agency
    • Law firm
    • Talent Acquisition
    • Audit & Certification
    Manufacturing
    • Textile
    • Metal
    • Furnitures
    • Food
    • Brewery
    • Corporate Gifts
    Health & Fitness
    • Sports Club
    • Eyewear Store
    • Fitness Center
    • Wellness Practitioners
    • Pharmacy
    • Hair Salon
    Trades
    • Handyman
    • IT Hardware & Support
    • Solar Energy Systems
    • Shoe Maker
    • Cleaning Services
    • HVAC Services
    Others
    • Nonprofit Organization
    • Environmental Agency
    • Billboard Rental
    • Photography
    • Bike Leasing
    • Software Reseller
    Browse all Industries
  • Community
    Learn
    • Tutorials
    • Documentation
    • Certifications
    • Training
    • Blog
    • Podcast
    Empower Education
    • Education Program
    • Scale Up! Business Game
    • Visit Odoo
    Get the Software
    • Download
    • Compare Editions
    • Releases
    Collaborate
    • Github
    • Forum
    • Events
    • Translations
    • Become a Partner
    • Services for Partners
    • Register your Accounting Firm
    Get Services
    • Find a Partner
    • Find an Accountant
    • Meet an advisor
    • Implementation Services
    • Customer References
    • Support
    • Upgrades
    Github Youtube Twitter Linkedin Instagram Facebook Spotify
    +1 (650) 691-3277
    Get a demo
  • Pricing
  • Help
  1. Mailing Lists
  2. Announcements
  3. Odoo Security Advisories - ODOO-SA-2018-11-28 | ODOO-SA-2018-08-07

Archives

  • By thread 36
  • By date
    • December 2017 7
    • February 2018 1
    • March 2018 1
    • April 2018 14
    • May 2018 5
    • June 2018 8
    • July 2018 6
    • August 2018 2
    • November 2018 2
    • January 2019 2
    • March 2019 1
    • April 2019 1
    • October 2019 1
    • December 2019 1
    • January 2020 1
    • July 2020 3
    • August 2020 1
    • December 2020 1
    • June 2022 1
    • September 2022 1
    • October 2022 1

Announcements

announcements@mail.odoo.com

Odoo Community & Enterprise

Odoo Security Advisory disclosure: ODOO-SA-2019-10-25

Odoo Security Advisories - ODOO-SA-2018-11-28 | ODOO-SA-2018-08-07

Several security advisories have just been disclosed, as described below.
Please be sure that your deployments are up-to-date. Follow the links at the end of the summary to read the detailed disclosure, including reference revision numbers and dates.

If you are unsure about the update process, please refer to our online instructions, valid for all versions:
  https://www.odoo.com/documentation/12.0/setup/update.html

Note: this is a notification of public disclosure of security issues from 2018 - the private disclosure already took place in 2018.
If you are using one of the Odoo Cloud-hosted services (Odoo Online | Odoo.SH) there is nothing to do, these updates were automatically applied as soon as the corrections were available.
If you have a valid Odoo Enterprise subscription, you have already been notified during the private disclosure - this only serves as a reminder.


~~~

# ODOO-SA-2018-11-28-1 (CVE-2018-15640)
  Severity :: High :: 8.1 :: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
  Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through
  12.0 allows remote authenticated attackers to obtain elevated privileges
  via a crafted request.
  https://github.com/odoo/odoo/issues/32514

# ODOO-SA-2018-11-28-2 (CVE-2018-15635)
  Severity :: Medium :: 5.9 :: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N
  Cross-site scripting vulnerability in the Discuss App of Odoo Community 12.0
  and earlier, and Odoo Enterprise 12.0 and earlier allows remote attackers to
  inject arbitrary web script in the browser of an internal user of the system
  by tricking them into inviting a follower on a document with a crafted name.
  https://github.com/odoo/odoo/issues/32515

# ODOO-SA-2018-11-28-3 (CVE-2018-15631)
  Severity :: Medium :: 6.5 :: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  Improper access control in the Discuss App of Odoo Community 12.0 and earlier
  and Odoo Enterprise 12.0 and earlier allows remote authenticated attackers to
  e-mail themselves arbitrary files from the database, via a crafted RPC
  request.
  https://github.com/odoo/odoo/issues/32516

~~~

# ODOO-SA-2018-08-07-1 (CVE-2018-14865)
  Severity: High :: 7.7
  Report engine in Odoo Community 11.0 and earlier and Odoo Enterprise
  11.0 and earlier does not use secure options when passing documents to
  wkhtmltopdf, which allows remote attackers to read local files.
  https://github.com/odoo/odoo/issues/32501

# ODOO-SA-2018-08-07-2 (CVE-2018-14864)
  Severity: Medium :: 6.3
  Incorrect access control in asset bundles in Odoo Community 11.0 and
  earlier and Odoo Enterprise 11.0 and earlier allows remote
  authenticated users to inject arbitrary web script via a crafted attachment.
  https://github.com/odoo/odoo/issues/32502

# ODOO-SA-2018-08-07-3 (CVE-2018-14867)
  Severity: Medium :: 6.5
  Incorrect access control in the portal messaging system in Odoo Community
  9.0 and 10.0 and Odoo Enterprise 9.0 and 10.0 allows remote attackers
  to post messages on behalf of customers, and to guess document
  attribute values, via crafted parameters.
  https://github.com/odoo/odoo/issues/32503

# ODOO-SA-2018-08-07-4 (CVE-2018-14862)
  Severity: High :: 7.1
  Incorrect access control in the mail templating system in Odoo Community
  11.0 and earlier and Odoo Enterprise 11.0 and earlier allows
  authenticated internal users to delete arbitrary menuitems via a crafted
  RPC request.
  https://github.com/odoo/odoo/issues/32504

# ODOO-SA-2018-08-07-5 (CVE-2018-14860)
  Severity: Critical :: 9.1
  Improper sanitization of dynamic user expressions in Odoo Community
  11.0 and earlier and Odoo Enterprise 11.0 and earlier allows
  authenticated privileged users to escape from the dynamic expression sandbox
  and execute arbitrary code on the hosting system.
  https://github.com/odoo/odoo/issues/32505

# ODOO-SA-2018-08-07-6 (CVE-2018-14861)
  Severity: Medium:: 4.3
  Improper data access control in Odoo Community 10.0 and 11.0 and Odoo
  Enterprise 10.0 and 11.0 allows authenticated users to perform a CSV export  
  of the secure hashed passwords of other users.
  https://github.com/odoo/odoo/issues/32506

# ODOO-SA-2018-08-07-7 (CVE-2018-14868)
  Severity: High:: 8.1
  Incorrect access control in the Password Encryption module in Odoo
  Community 9.0 and Odoo Enterprise 9.0 allows authenticated users to
  change the password of other users without knowing their current
  password via a crafted RPC call.
  https://github.com/odoo/odoo/issues/32507

# ODOO-SA-2018-08-07-8 (CVE-2018-14863)
  Severity: High :: 8.1
  Incorrect access control in the RPC framework in Odoo Community 8.0
  through 11.0 and Odoo Enterprise 9.0 through 11.0 allows authenticated
  users to call private functions via RPC.
  https://github.com/odoo/odoo/issues/32508

# ODOO-SA-2018-08-07-9 (CVE-2018-14866)
  Severity: Low :: 3.5
  Incorrect access control in the TransientModel framework in Odoo
  Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows
  authenticated attackers to access data in transient records that they
  do not own by making an RPC call before garbage collection occurs.
  https://github.com/odoo/odoo/issues/32509

# ODOO-SA-2018-08-07-10 (CVE-2018-14859)
  Severity: High :: 8.1
  Incorrect access control in the password reset component in Odoo
  Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows
  authenticated users to reset the password of other users by being the first
  party to use the secure token.
  https://github.com/odoo/odoo/issues/32510

# ODOO-SA-2018-08-07-11 (CVE-2018-14887)
  Severity: High :: 6.5
  Improper Host header sanitization in the dbfilter routing component in Odoo
  Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows
  a remote attacker to deny access to the service and to disclose
  database names via a crafted request.
  https://github.com/odoo/odoo/issues/32511

# ODOO-SA-2018-08-07-12 (CVE-2018-14885)
  Severity: High :: 8.2
  Incorrect access control in the database manager component in Odoo
  Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a
  remote attacker to restore a database dump without knowing the
  super-admin password. An arbitrary password succeeds.
  https://github.com/odoo/odoo/issues/32512


# ODOO-SA-2018-08-07-13 (CVE-2018-14886)
  Severity: High :: 6.8
  The module-description renderer in Odoo Community 11.0 and earlier and Odoo
  Enterprise 11.0 and earlier does not disable RST's local file
  inclusion, which allows privileged authenticated users to read local
  files via a crafted module description.
  https://github.com/odoo/odoo/issues/32513


by Olivier Dony (odo) - 10:21 - 8 Apr 2019
Community
  • Tutorials
  • Documentation
  • Forum
Open Source
  • Download
  • Github
  • Runbot
  • Translations
Services
  • Odoo.sh Hosting
  • Support
  • Upgrade
  • Custom Developments
  • Education
  • Find an Accountant
  • Find a Partner
  • Become a Partner
About us
  • Our company
  • Brand Assets
  • Contact us
  • Jobs
  • Events
  • Podcast
  • Blog
  • Customers
  • Legal • Privacy
  • Security
الْعَرَبيّة Català 简体中文 繁體中文 (台灣) Čeština Dansk Nederlands English Suomi Français Deutsch हिंदी Bahasa Indonesia Italiano 日本語 한국어 (KR) Lietuvių kalba Język polski Português (BR) română русский язык Slovenský jazyk slovenščina Español (América Latina) Español ภาษาไทย Türkçe українська Tiếng Việt

Odoo is a suite of open source business apps that cover all your company needs: CRM, eCommerce, accounting, inventory, point of sale, project management, etc.

Odoo's unique value proposition is to be at the same time very easy to use and fully integrated.

Website made with

Odoo Experience on YouTube

1. Use the live chat to ask your questions.
2. The operator answers within a few minutes.

Live support on Youtube
Watch now