Skip to Content
Odoo Menu
  • Prihlásiť sa
  • Vyskúšajte zadarmo
  • Aplikácie
    Financie
    • Účtovníctvo
    • Fakturácia
    • Výdavky
    • Tabuľka (BI)
    • Dokumenty
    • Podpis
    Predaj
    • CRM
    • Predaj
    • POS Shop
    • POS Restaurant
    • Manažment odberu
    • Požičovňa
    Webstránky
    • Tvorca webstránok
    • eShop
    • Blog
    • Fórum
    • Živý chat
    • eLearning
    Supply Chain
    • Sklad
    • Výroba
    • Správa životného cyklu produktu
    • Nákup
    • Údržba
    • Manažment kvality
    Ľudské zdroje
    • Zamestnanci
    • Nábor zamestnancov
    • Voľné dni
    • Hodnotenia
    • Odporúčania
    • Vozový park
    Marketing
    • Marketing sociálnych sietí
    • Email marketing
    • SMS marketing
    • Eventy
    • Marketingová automatizácia
    • Prieskumy
    Služby
    • Projektové riadenie
    • Pracovné výkazy
    • Práca v teréne
    • Helpdesk
    • Plánovanie
    • Schôdzky
    Produktivita
    • Tímová komunikácia
    • Schvalovania
    • IoT
    • VoIP
    • Znalosti
    • WhatsApp
    Third party apps Odoo Studio Odoo Cloud Platform
  • Priemyselné odvetvia
    Retail
    • Book Store
    • Clothing Store
    • Furniture Store
    • Grocery Store
    • Hardware Store
    • Toy Store
    Food & Hospitality
    • Bar and Pub
    • Reštaurácia
    • Fast Food
    • Guest House
    • Beverage distributor
    • Hotel
    Reality
    • Real Estate Agency
    • Architecture Firm
    • Konštrukcia
    • Estate Managament
    • Gardening
    • Property Owner Association
    Poradenstvo
    • Accounting Firm
    • Odoo Partner
    • Marketing Agency
    • Law firm
    • Talent Acquisition
    • Audit & Certification
    Výroba
    • Textile
    • Metal
    • Furnitures
    • Jedlo
    • Brewery
    • Corporate Gifts
    Health & Fitness
    • Sports Club
    • Eyewear Store
    • Fitness Center
    • Wellness Practitioners
    • Pharmacy
    • Hair Salon
    Trades
    • Handyman
    • IT Hardware and Support
    • Solar Energy Systems
    • Shoe Maker
    • Cleaning Services
    • HVAC Services
    Iní
    • Nonprofit Organization
    • Environmental Agency
    • Billboard Rental
    • Photography
    • Bike Leasing
    • Software Reseller
    Browse all Industries
  • Komunita
    Vzdelávanie
    • Tutoriály
    • Dokumentácia
    • Certifikácie
    • Školenie
    • Blog
    • Podcast
    Empower Education
    • Vzdelávací program
    • Scale Up! Business Game
    • Visit Odoo
    Softvér
    • Stiahnuť
    • Porovnanie Community a Enterprise vierzie
    • Releases
    Spolupráca
    • Github
    • Fórum
    • Eventy
    • Preklady
    • Staň sa partnerom
    • Services for Partners
    • Register your Accounting Firm
    Služby
    • Nájdite partnera
    • Nájdite účtovníka
    • Meet an advisor
    • Implementation Services
    • Zákaznícke referencie
    • Podpora
    • Upgrades
    ​Github Youtube Twitter Linkedin Instagram Facebook Spotify
    +1 (650) 691-3277
    Získajte demo
  • Cenník
  • Pomoc

Vulnerability policy: Open Redirectors

Why we ask you NOT to report those

Why do security researchers consider Open Redirects a vulnerability?

Open Redirects are indeed seen as a vulnerability by some members of the security community.

Most of the time it is because the OWASP Top 10 (v2010/2013) used to include it at the last position ("A10: Unvalidated Redirects and Forwards").

The main argument for this entry is that users could be duped into trusting the link because the tooltip shows a known domain name, and may not notice the change of domain name after the navigation occurs. However, the OWASP description of the issue explains that this is only one way to conduct a phishing attack.
It is not a direct vulnerability of the website, and cannot be abused by an attacker easily, unless another issue is present.


Why doesn't Odoo consider this a vulnerability?

In modern browsers, the address bar is the only reliable content origin indicator available. Browsers put a lot of efforts to provide visible security feedback in the address bar (SSL certificates, etc.) This is why Odoo recommends the use of valid SSL certificates in order to help the user identify changes in the address bar (Odoo Online is running exclusively on HTTPS).

On the other hand, tooltips can be easily forged and must never be trusted as security indicators!

More importantly, any user who could be fooled by a phishing tooltip could also be fooled without using an open redirect link. It is a common technique for attackers to register a similar domain name and send emails with phishing links bringing to the fake website. Eliminating URL redirectors will not block this, so it will not increase much the security of the users. But it would break some features that our users are actively depending on, or make Odoo deployments more complex.

So we don't consider open URL redirect reports as valid security issues, unless they can be chained with other real exploits such as XSS by redirecting to a data: or javascript: URL. If you find a real exploitable scenario with a directly exploitable XSS, please report it. (Note: modern browsers block those unsafe redirects in most cases now)

 

But isn't Odoo wrong? Other people seem to accept this vulnerability!

No, really, we're not alone there ;-)

If you're not convinced by the above, we have other reasons to be comforted in our position:

  • Open Redirects have now been dropped from the OWASP Top 10 2017, after feedback from the security community. You can find the OWASP Top 10 2017 here. You can also see the explanation for the removal of issue "A10-Unvalidated Redirects and Forwards" in the release notes (p.4).

  • Many application vendors share our policy. For example Google and Yahoo/Verizon don't accept Open Redirects ("Intentional Open Redirects") issues either, for the same reasons.


Komunita
  • Tutoriály
  • Dokumentácia
  • Fórum
Open Source
  • Stiahnuť
  • Github
  • Runbot
  • Preklady
Služby
  • Odoo.sh hosting
  • Podpora
  • Vyššia verzia
  • Custom Developments
  • Vzdelávanie
  • Nájdite účtovníka
  • Nájdite partnera
  • Staň sa partnerom
O nás
  • Naša spoločnosť
  • Majetok značky
  • Kontaktujte nás
  • Pracovné ponuky
  • Eventy
  • Podcast
  • Blog
  • Zákazníci
  • Právne dokumenty • Súkromie
  • Bezpečnosť
الْعَرَبيّة Català 简体中文 繁體中文 (台灣) Čeština Dansk Nederlands English Suomi Français Deutsch हिंदी Bahasa Indonesia Italiano 日本語 한국어 (KR) Lietuvių kalba Język polski Português (BR) română русский язык Slovenský jazyk slovenščina Español (América Latina) Español ภาษาไทย Türkçe українська Tiếng Việt

Odoo je sada podnikových aplikácií s otvoreným zdrojovým kódom, ktoré pokrývajú všetky potreby vašej spoločnosti: CRM, e-shop, účtovníctvo, skladové hospodárstvo, miesto predaja, projektový manažment atď.

Odoo prináša vysokú pridanú hodnotu v jednoduchom použití a súčasne plne integrovanými biznis aplikáciami.

Website made with

Odoo Experience on YouTube

1. Use the live chat to ask your questions.
2. The operator answers within a few minutes.

Live support on Youtube
Watch now