Skip to Content
Odoo Menu
  • Prijavi
  • Try it free
  • Aplikacije
    Finance
    • Knjigovodstvo
    • Obračun
    • Stroški
    • Spreadsheet (BI)
    • Dokumenti
    • Podpisovanje
    Prodaja
    • CRM
    • Prodaja
    • POS Shop
    • POS Restaurant
    • Naročnine
    • Najem
    Spletne strani
    • Website Builder
    • Spletna trgovina
    • Blog
    • Forum
    • Pogovor v živo
    • eUčenje
    Dobavna veriga
    • Zaloga
    • Proizvodnja
    • PLM
    • Nabava
    • Vzdrževanje
    • Kakovost
    Kadri
    • Kadri
    • Kadrovanje
    • Odsotnost
    • Ocenjevanja
    • Priporočila
    • Vozni park
    Marketing
    • Družbeno Trženje
    • Email Marketing
    • SMS Marketing
    • Dogodki
    • Avtomatizacija trženja
    • Ankete
    Storitve
    • Projekt
    • Časovnice
    • Storitve na terenu
    • Služba za pomoč
    • Načrtovanje
    • Termini
    Produktivnost
    • Razprave
    • Odobritve
    • IoT
    • Voip
    • Znanje
    • WhatsApp
    Third party apps Odoo Studio Odoo Cloud Platform
  • Industrije
    Trgovina na drobno
    • Book Store
    • Trgovina z oblačili
    • Trgovina s pohištvom
    • Grocery Store
    • Trgovina s strojno opremo računalnikov
    • Trgovina z igračami
    Food & Hospitality
    • Bar and Pub
    • Restavracija
    • Hitra hrana
    • Guest House
    • Beverage Distributor
    • Hotel
    Nepremičnine
    • Real Estate Agency
    • Arhitekturno podjetje
    • Gradbeništvo
    • Estate Management
    • Vrtnarjenje
    • Združenje lastnikov nepremičnin
    Svetovanje
    • Računovodsko podjetje
    • Odoo Partner
    • Marketinška agencija
    • Law firm
    • Pridobivanje talentov
    • Audit & Certification
    Proizvodnja
    • Tekstil
    • Metal
    • Pohištvo
    • Hrana
    • Brewery
    • Poslovna darila
    Health & Fitness
    • Športni klub
    • Trgovina z očali
    • Fitnes center
    • Wellness Practitioners
    • Lekarna
    • Frizerski salon
    Trades
    • Handyman
    • IT Hardware & Support
    • Sistemi sončne energije
    • Izdelovalec čevljev
    • Čistilne storitve
    • HVAC Services
    Ostali
    • Neprofitna organizacija
    • Agencija za okolje
    • Najem oglasnih panojev
    • Fotografija
    • Najem koles
    • Prodajalec programske opreme
    Browse all Industries
  • Skupnost
    Learn
    • Tutorials
    • Dokumentacija
    • Certifikati
    • Šolanje
    • Blog
    • Podcast
    Empower Education
    • Education Program
    • Scale Up! Business Game
    • Visit Odoo
    Get the Software
    • Prenesi
    • Compare Editions
    • Releases
    Collaborate
    • Github
    • Forum
    • Dogodki
    • Prevodi
    • Become a Partner
    • Services for Partners
    • Register your Accounting Firm
    Get Services
    • Find a Partner
    • Find an Accountant
    • Meet an advisor
    • Implementation Services
    • Sklici kupca
    • Podpora
    • Upgrades
    Github Youtube Twitter Linkedin Instagram Facebook Spotify
    +1 (650) 691-3277
    Get a demo
  • Določanje cen
  • Pomoč

Vulnerability policy: Open Redirectors

Why we ask you NOT to report those

Why do security researchers consider Open Redirects a vulnerability?

Open Redirects are indeed seen as a vulnerability by some members of the security community.

Most of the time it is because the OWASP Top 10 (v2010/2013) used to include it at the last position ("A10: Unvalidated Redirects and Forwards").

The main argument for this entry is that users could be duped into trusting the link because the tooltip shows a known domain name, and may not notice the change of domain name after the navigation occurs. However, the OWASP description of the issue explains that this is only one way to conduct a phishing attack.
It is not a direct vulnerability of the website, and cannot be abused by an attacker easily, unless another issue is present.


Why doesn't Odoo consider this a vulnerability?

In modern browsers, the address bar is the only reliable content origin indicator available. Browsers put a lot of efforts to provide visible security feedback in the address bar (SSL certificates, etc.) This is why Odoo recommends the use of valid SSL certificates in order to help the user identify changes in the address bar (Odoo Online is running exclusively on HTTPS).

On the other hand, tooltips can be easily forged and must never be trusted as security indicators!

More importantly, any user who could be fooled by a phishing tooltip could also be fooled without using an open redirect link. It is a common technique for attackers to register a similar domain name and send emails with phishing links bringing to the fake website. Eliminating URL redirectors will not block this, so it will not increase much the security of the users. But it would break some features that our users are actively depending on, or make Odoo deployments more complex.

So we don't consider open URL redirect reports as valid security issues, unless they can be chained with other real exploits such as XSS by redirecting to a data: or javascript: URL. If you find a real exploitable scenario with a directly exploitable XSS, please report it. (Note: modern browsers block those unsafe redirects in most cases now)

 

But isn't Odoo wrong? Other people seem to accept this vulnerability!

No, really, we're not alone there ;-)

If you're not convinced by the above, we have other reasons to be comforted in our position:

  • Open Redirects have now been dropped from the OWASP Top 10 2017, after feedback from the security community. You can find the OWASP Top 10 2017 here. You can also see the explanation for the removal of issue "A10-Unvalidated Redirects and Forwards" in the release notes (p.4).

  • Many application vendors share our policy. For example Google and Yahoo/Verizon don't accept Open Redirects ("Intentional Open Redirects") issues either, for the same reasons.


Community
  • Tutorials
  • Dokumentacija
  • Forum
Open Source
  • Prenesi
  • Github
  • Runbot
  • Prevodi
Services
  • Odoo.sh Hosting
  • Podpora
  • Nadgradnja
  • Custom Developments
  • Izobraževanje
  • Find an Accountant
  • Find a Partner
  • Become a Partner
About us
  • Our company
  • Sredstva blagovne znamke
  • Kontakt
  • Zaposlitve
  • Dogodki
  • Podcast
  • Blog
  • Stranke
  • Pravno • Zasebnost
  • Varnost
الْعَرَبيّة Català 简体中文 繁體中文 (台灣) Čeština Dansk Nederlands English Suomi Français Deutsch हिंदी Bahasa Indonesia Italiano 日本語 한국어 (KR) Lietuvių kalba Język polski Português (BR) română русский язык Slovenský jazyk slovenščina Español (América Latina) Español ภาษาไทย Türkçe українська Tiếng Việt

Odoo is a suite of open source business apps that cover all your company needs: CRM, eCommerce, accounting, inventory, point of sale, project management, etc.

Odoo's unique value proposition is to be at the same time very easy to use and fully integrated.

Website made with

Odoo Experience on YouTube

1. Use the live chat to ask your questions.
2. The operator answers within a few minutes.

Live support on Youtube
Watch now