Passa al contenuto
Odoo Menu
  • Accedi
  • Provalo gratis
  • App
    Finanze
    • Contabilità
    • Fatturazione
    • Note spese
    • Fogli di calcolo (BI)
    • Documenti
    • Firma
    Vendite
    • CRM
    • Vendite
    • Punto vendita Negozio
    • Punto vendita Ristorante
    • Abbonamenti
    • Noleggi
    Siti web
    • Configuratore sito web
    • E-commerce
    • Blog
    • Forum
    • Live chat
    • E-learning
    Supply chain
    • Magazzino
    • Produzione
    • PLM
    • Acquisti
    • Manutenzione
    • Qualità
    Risorse umane
    • Dipendenti
    • Assunzioni
    • Ferie
    • Valutazioni
    • Referral dipendenti
    • Parco veicoli
    Marketing
    • Social marketing
    • E-mail marketing
    • SMS marketing
    • Eventi
    • Marketing automation
    • Sondaggi
    Servizi
    • Progetti
    • Fogli ore
    • Assistenza sul campo
    • Helpdesk
    • Pianificazione
    • Appuntamenti
    Produttività
    • Comunicazioni
    • Approvazioni
    • IoT
    • VoIP
    • Knowledge
    • WhatsApp
    App di terze parti Odoo Studio Piattaforma cloud Odoo
  • Settori
    Retail
    • Libreria
    • Negozio di abbigliamento
    • Negozio di arredamento
    • Alimentari
    • Ferramenta
    • Negozio di giocattoli
    Cibo e ospitalità
    • Bar e pub
    • Ristorante
    • Fast food
    • Pensione
    • Grossista di bevande
    • Hotel
    Agenzia immobiliare
    • Agenzia immobiliare
    • Studio di architettura
    • Edilizia
    • Gestione immobiliare
    • Impresa di giardinaggio
    • Associazione di proprietari immobiliari
    Consulenza
    • Società di contabilità
    • Partner Odoo
    • Agenzia di marketing
    • Studio legale
    • Selezione del personale
    • Audit e certificazione
    Produzione
    • Tessile
    • Metallo
    • Arredamenti
    • Alimentare
    • Birrificio
    • Ditta di regalistica aziendale
    Benessere e sport
    • Club sportivo
    • Negozio di ottica
    • Centro fitness
    • Centro benessere
    • Farmacia
    • Parrucchiere
    Commercio
    • Tuttofare
    • Hardware e assistenza IT
    • Ditta di installazione di pannelli solari
    • Calzolaio
    • Servizi di pulizia
    • Servizi di climatizzazione
    Altro
    • Organizzazione non profit
    • Ente per la tutela ambientale
    • Agenzia di cartellonistica pubblicitaria
    • Studio fotografico
    • Punto noleggio di biciclette
    • Rivenditore di software
    Carica tutti i settori
  • Community
    Apprendimento
    • Tutorial
    • Documentazione
    • Certificazioni 
    • Formazione
    • Blog
    • Podcast
    Potenzia la tua formazione
    • Programma educativo
    • Scale Up! Business Game
    • Visita Odoo
    Ottieni il software
    • Scarica
    • Versioni a confronto
    • Note di versione
    Collabora
    • Github
    • Forum
    • Eventi
    • Traduzioni
    • Diventa nostro partner
    • Servizi per partner
    • Registra la tua società di contabilità
    Ottieni servizi
    • Trova un partner
    • Trova un contabile
    • Incontra un esperto
    • Servizi di implementazione
    • Testimonianze dei clienti
    • Supporto
    • Aggiornamenti
    GitHub Youtube Twitter Linkedin Instagram Facebook Spotify
    +1 (650) 691-3277
    Richiedi una demo
  • Prezzi
  • Aiuto
  1. Mailing list
  2. Announcements
  3. Odoo Security Advisories - ODOO-SA-2018-11-28 | ODOO-SA-2018-08-07

Archivi

  • Per thread 36
  • Per data
    • dicembre 2017 7
    • febbraio 2018 1
    • marzo 2018 1
    • aprile 2018 14
    • maggio 2018 5
    • giugno 2018 8
    • luglio 2018 6
    • agosto 2018 2
    • novembre 2018 2
    • gennaio 2019 2
    • marzo 2019 1
    • aprile 2019 1
    • ottobre 2019 1
    • dicembre 2019 1
    • gennaio 2020 1
    • luglio 2020 3
    • agosto 2020 1
    • dicembre 2020 1
    • giugno 2022 1
    • settembre 2022 1
    • ottobre 2022 1

Announcements

announcements@mail.odoo.com

Odoo Community & Enterprise

Odoo Security Advisory disclosure: ODOO-SA-2019-10-25

Odoo Security Advisories - ODOO-SA-2018-11-28 | ODOO-SA-2018-08-07

Several security advisories have just been disclosed, as described below.
Please be sure that your deployments are up-to-date. Follow the links at the end of the summary to read the detailed disclosure, including reference revision numbers and dates.

If you are unsure about the update process, please refer to our online instructions, valid for all versions:
  https://www.odoo.com/documentation/12.0/setup/update.html

Note: this is a notification of public disclosure of security issues from 2018 - the private disclosure already took place in 2018.
If you are using one of the Odoo Cloud-hosted services (Odoo Online | Odoo.SH) there is nothing to do, these updates were automatically applied as soon as the corrections were available.
If you have a valid Odoo Enterprise subscription, you have already been notified during the private disclosure - this only serves as a reminder.


~~~

# ODOO-SA-2018-11-28-1 (CVE-2018-15640)
  Severity :: High :: 8.1 :: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
  Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through
  12.0 allows remote authenticated attackers to obtain elevated privileges
  via a crafted request.
  https://github.com/odoo/odoo/issues/32514

# ODOO-SA-2018-11-28-2 (CVE-2018-15635)
  Severity :: Medium :: 5.9 :: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N
  Cross-site scripting vulnerability in the Discuss App of Odoo Community 12.0
  and earlier, and Odoo Enterprise 12.0 and earlier allows remote attackers to
  inject arbitrary web script in the browser of an internal user of the system
  by tricking them into inviting a follower on a document with a crafted name.
  https://github.com/odoo/odoo/issues/32515

# ODOO-SA-2018-11-28-3 (CVE-2018-15631)
  Severity :: Medium :: 6.5 :: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  Improper access control in the Discuss App of Odoo Community 12.0 and earlier
  and Odoo Enterprise 12.0 and earlier allows remote authenticated attackers to
  e-mail themselves arbitrary files from the database, via a crafted RPC
  request.
  https://github.com/odoo/odoo/issues/32516

~~~

# ODOO-SA-2018-08-07-1 (CVE-2018-14865)
  Severity: High :: 7.7
  Report engine in Odoo Community 11.0 and earlier and Odoo Enterprise
  11.0 and earlier does not use secure options when passing documents to
  wkhtmltopdf, which allows remote attackers to read local files.
  https://github.com/odoo/odoo/issues/32501

# ODOO-SA-2018-08-07-2 (CVE-2018-14864)
  Severity: Medium :: 6.3
  Incorrect access control in asset bundles in Odoo Community 11.0 and
  earlier and Odoo Enterprise 11.0 and earlier allows remote
  authenticated users to inject arbitrary web script via a crafted attachment.
  https://github.com/odoo/odoo/issues/32502

# ODOO-SA-2018-08-07-3 (CVE-2018-14867)
  Severity: Medium :: 6.5
  Incorrect access control in the portal messaging system in Odoo Community
  9.0 and 10.0 and Odoo Enterprise 9.0 and 10.0 allows remote attackers
  to post messages on behalf of customers, and to guess document
  attribute values, via crafted parameters.
  https://github.com/odoo/odoo/issues/32503

# ODOO-SA-2018-08-07-4 (CVE-2018-14862)
  Severity: High :: 7.1
  Incorrect access control in the mail templating system in Odoo Community
  11.0 and earlier and Odoo Enterprise 11.0 and earlier allows
  authenticated internal users to delete arbitrary menuitems via a crafted
  RPC request.
  https://github.com/odoo/odoo/issues/32504

# ODOO-SA-2018-08-07-5 (CVE-2018-14860)
  Severity: Critical :: 9.1
  Improper sanitization of dynamic user expressions in Odoo Community
  11.0 and earlier and Odoo Enterprise 11.0 and earlier allows
  authenticated privileged users to escape from the dynamic expression sandbox
  and execute arbitrary code on the hosting system.
  https://github.com/odoo/odoo/issues/32505

# ODOO-SA-2018-08-07-6 (CVE-2018-14861)
  Severity: Medium:: 4.3
  Improper data access control in Odoo Community 10.0 and 11.0 and Odoo
  Enterprise 10.0 and 11.0 allows authenticated users to perform a CSV export  
  of the secure hashed passwords of other users.
  https://github.com/odoo/odoo/issues/32506

# ODOO-SA-2018-08-07-7 (CVE-2018-14868)
  Severity: High:: 8.1
  Incorrect access control in the Password Encryption module in Odoo
  Community 9.0 and Odoo Enterprise 9.0 allows authenticated users to
  change the password of other users without knowing their current
  password via a crafted RPC call.
  https://github.com/odoo/odoo/issues/32507

# ODOO-SA-2018-08-07-8 (CVE-2018-14863)
  Severity: High :: 8.1
  Incorrect access control in the RPC framework in Odoo Community 8.0
  through 11.0 and Odoo Enterprise 9.0 through 11.0 allows authenticated
  users to call private functions via RPC.
  https://github.com/odoo/odoo/issues/32508

# ODOO-SA-2018-08-07-9 (CVE-2018-14866)
  Severity: Low :: 3.5
  Incorrect access control in the TransientModel framework in Odoo
  Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows
  authenticated attackers to access data in transient records that they
  do not own by making an RPC call before garbage collection occurs.
  https://github.com/odoo/odoo/issues/32509

# ODOO-SA-2018-08-07-10 (CVE-2018-14859)
  Severity: High :: 8.1
  Incorrect access control in the password reset component in Odoo
  Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows
  authenticated users to reset the password of other users by being the first
  party to use the secure token.
  https://github.com/odoo/odoo/issues/32510

# ODOO-SA-2018-08-07-11 (CVE-2018-14887)
  Severity: High :: 6.5
  Improper Host header sanitization in the dbfilter routing component in Odoo
  Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows
  a remote attacker to deny access to the service and to disclose
  database names via a crafted request.
  https://github.com/odoo/odoo/issues/32511

# ODOO-SA-2018-08-07-12 (CVE-2018-14885)
  Severity: High :: 8.2
  Incorrect access control in the database manager component in Odoo
  Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a
  remote attacker to restore a database dump without knowing the
  super-admin password. An arbitrary password succeeds.
  https://github.com/odoo/odoo/issues/32512


# ODOO-SA-2018-08-07-13 (CVE-2018-14886)
  Severity: High :: 6.8
  The module-description renderer in Odoo Community 11.0 and earlier and Odoo
  Enterprise 11.0 and earlier does not disable RST's local file
  inclusion, which allows privileged authenticated users to read local
  files via a crafted module description.
  https://github.com/odoo/odoo/issues/32513


da Olivier Dony (odo) - 10:21 - 8 apr 2019
Community
  • Tutorial
  • Documentazione
  • Forum
Open source
  • Scarica
  • Github
  • Runbot
  • Traduzioni
Servizi
  • Hosting Odoo.sh
  • Supporto
  • Aggiornamenti
  • Sviluppi personalizzati
  • Formazione
  • Trova un contabile
  • Trova un partner
  • Diventa nostro partner
Chi siamo
  • La nostra azienda
  • Branding
  • Contattaci
  • Lavora con noi
  • Eventi
  • Podcast
  • Blog
  • Clienti
  • Note legali • Privacy
  • Sicurezza
الْعَرَبيّة Català 简体中文 繁體中文 (台灣) Čeština Dansk Nederlands English Suomi Français Deutsch हिंदी Bahasa Indonesia Italiano 日本語 한국어 (KR) Lietuvių kalba Język polski Português (BR) română русский язык Slovenský jazyk slovenščina Español (América Latina) Español ภาษาไทย Türkçe українська Tiếng Việt

Odoo è un gestionale di applicazioni aziendali open source pensato per coprire tutte le esigenze della tua azienda: CRM, Vendite, E-commerce, Magazzino, Produzione, Fatturazione elettronica, Project Management e molto altro.

Il punto di forza di Odoo è quello di offrire un ecosistema unico di app facili da usare, intuitive e completamente integrate tra loro.

Website made with

Odoo Experience on YouTube

1. Use the live chat to ask your questions.
2. The operator answers within a few minutes.

Live support on Youtube
Watch now