跳至内容
Odoo 菜单
  • 登录
  • 免费试用
  • 应用程序
    财务
    • 会计
    • 发票
    • 费用
    • 电子表格 (BI)
    • 文档
    • 电子签名
    销售
    • 客户关系管理
    • 销售
    • POS 销售点管理-零售
    • POS 销售点管理 - 餐厅
    • 订阅
    • 租赁
    网站
    • 网站设计
    • 电子商务
    • 博客
    • 论坛
    • 在线客服
    • 在线学习
    供应链
    • 库存
    • 制造
    • 产品生命周期
    • 采购
    • 维护保养
    • 品控
    人力资源
    • 员工
    • 招聘
    • 休假
    • 评价
    • 内部推荐
    • 车队
    营销
    • 社媒营销
    • 电邮营销
    • 短信营销
    • 近期活动
    • 营销自动化
    • 网上调查
    服务
    • 项目管理
    • 工时单
    • 现场服务
    • 服务台
    • 排期
    • 预约
    生产力
    • 讨论
    • 人工智能
    • IoT物联网
    • VoIP
    • 知识库
    • WhatsApp
    第三方应用软件 Odoo 定制 Odoo云端平台
  • 行业
    零售
    • 书店
    • 服装店
    • 家具店
    • 食品杂货店
    • 五金店
    • 玩具店
    餐饮与酒店服务
    • 酒吧及酒馆
    • 餐厅
    • 快餐
    • 民宿
    • 饮品分销商
    • 酒店
    房地产
    • 房地产代理
    • 建筑师事务所
    • 建造业
    • 物业管理
    • 园艺
    • 业主协会
    咨询
    • 会计师事务所
    • Odoo合作伙伴
    • 市场推广公司
    • 律师事务所
    • 人才招聘
    • 审核 & 认证
    制造
    • 纺织
    • 金属
    • 家具
    • 食品
    • 啤酒厂
    • 企业礼品
    保健与健身
    • 体育俱乐部
    • 眼镜店
    • 健身中心
    • 健康从业者
    • 药房
    • 发型屋
    商贸服务
    • 维修人员
    • IT 硬件及支持
    • 太阳能系统
    • 鞋匠
    • 清洁服务
    • 暖通空调服务
    其他
    • 非营利组织
    • 环境机构
    • 广告牌租赁
    • 摄影服务
    • 自行车租赁
    • 软件经销商
    浏览所有行业⟶
  • 社区
    学习
    • 教学视频
    • 文档
    • 认证
    • 培训
    • 博客
    • 播客
    赋能教育
    • 教育计划
    • Scale Up! 商业游戏
    • 参观Odoo
    获取软件
    • 下载
    • 版本对比
    • 发布
    合作
    • Github
    • 论坛
    • 近期活动
    • 翻译
    • 成为合作伙伴
    • 合作伙伴服务
    • 注册您的会计事务所
    • 联盟计划
    获取服务
    • 寻找合作伙伴
    • 查找会计服务
    • 预约顾问咨询
    • 安装及推行服务
    • 客户参考
    • 支持
    • 升级
    Github Youtube Twitter Linkedin Instagram Facebook Spotify
    +1 (650) 691-3277
    获取演示
  • 定价
  • 技术支持

Odoo 安全性政策

Security is a core part of how we design, operate, and maintain Odoo. This page summarizes the security practices and safeguards we apply to Odoo Cloud and the Odoo software.

— Odoo 云端版(该平台)—

CSA STAR 第1级别

Odoo 参与了云安全联盟(CSA)的安全、信任、保证和风险 (STAR) 计划。 查看我们对 CAIQv3.1 问卷的回答

备份/灾难修复

  • We maintain a history of 14 full backups of each Odoo database for at least 3 months: daily backups for 7 days, weekly backups for 4 weeks, and monthly backups for 3 months.
  • 备份数据至少复制到 3 个不同的数据中心。
  • 有关数据中心的实际位置,请参阅我们的 隐私政策.
  • 你还可以在任何时候使用控制面板下载实时数据的手动备份。
  • You can contact our Helpdesk to restore an available backup to your live database or to a separate database.
  • 硬件故障转移:对于裸机托管的服务,如果硬件出现故障,我们会实施本地热备复制,并持续监控,故障时手动转移程序。
  • Disaster recovery: we maintain disaster recovery procedures designed to restore Odoo Cloud services and customer data following major infrastructure failures or disasters. See our Cloud Service Level Agreement for more details and detailed Recovery Point Objectives (RPO) and Recovery Time Objectives (RTO).

数据库安全

  • Customer data is stored in a dedicated database and is not shared between customers.
  • Data access controls isolate customer databases running on the same cluster, preventing access from one customer database to another.

密码安全

  • Customer passwords are protected using industry-standard PBKDF2+SHA512 password hashing, with salting and key stretching over thousands of rounds.
  • Odoo staff cannot access or retrieve your password. If a password is lost, it must be reset.
  • 登录凭证始终通过 HTTPS 安全传输。
  • Customer database administrators can 为登录速率设置限制 and cooldown periods for repeated login attempts.
  • Password policies: database administrators can enforce a minimum user password length. Other policies, such as required character classes, are not enabled by default because research has shown them to be counterproductive. See [[Shay et al. 2016]。] and NIST SP 800-63b.

员工访问

  • Odoo Helpdesk staff may access your account when necessary to investigate a support issue. They use dedicated staff credentials rather than your password, which they cannot access.
  • Dedicated staff access allows our teams to reproduce reported issues without requiring you to share your password, while enabling staff actions to be separately controlled and audited.
  • Helpdesk staff limit their access to the data, files, and settings necessary to diagnose and resolve your issue.

系统安全

  • 所有 Odoo 云端服务器都运行经过强化的 Linux 发行版,并具有最新安全补丁。
  • Server installations are purpose-built and minimal, reducing the number of services that could introduce vulnerabilities.
  • Remote server administration is restricted to a small number of trusted Odoo engineers and protected with personal multi-factor credentials.

实体安全

Odoo Cloud servers are hosted in trusted data centers across multiple regions. All hosting facilities must meet our physical security requirements, including:

  • Restricted perimeters accessible only to authorized data center personnel.
  • Physical access controls using security badges or biometric authentication.
  • 24/7 security camera monitoring of data center facilities.
  • 24/7 on-site security personnel.

信用卡安全

  • We do not store credit card information on our systems.
  • Credit card information is transmitted securely and directly to 符合 PCI 标准 payment acquirers. See our 隐私政策 for the list of providers.

数据加密

Customer data is encrypted both in transit and at rest.
  • Communications with customer instances are protected using HTTPS with 256-bit SSL encryption.
  • Internal communications between servers are protected with end-to-end encryption.
  • Our servers are continuously monitored and kept up to date with patches for SSL vulnerabilities.
  • Our SSL certificates use 2048-bit keys with full SHA-2 certificate chains. You can verify the SSL rating 这里.
  • Customer data, including database contents and stored files, is encrypted at rest with AES-256 in both production systems and backups.

网络防御

  • Data centers providers used for Odoo Cloud operate high-capacity networks designed to withstand large volumes inluding most Denial of Service attacks. Automated and manual mitigation systems detect and divert attack traffic at the network edge before it can disrupt service availability.
  • Odoo 云端服务器上的防火墙和入侵防御系统,有助于检测和阻止暴力破解密码攻击等威胁。
  • Customer database administrators can 为登录速率设置限制 并且为重复登录尝试设置冷却时间,或配置验证码以减轻自动暴力破解攻击。

— Odoo(该软件)—

软件安全

Odoo is open source, allowing its codebase to be continuously reviewed by users and contributors worldwide. Community reports are an important source of security feedback, and we encourage developers and security researchers to audit the code and report security issues.

Odoo R&D processes include code reviews that consider security aspects for both new and contributed code.

安全始于设计

The Odoo framework is designed to prevent common classes of security vulnerabilities by default:

  • SQL injection is prevented by a higher-level API that generally removes the need for manually constructed SQL queries.
  • Cross-site scripting (XSS) is prevented by a high-level templating system that automatically escapes injected data.
  • The framework prevents RPC access to private methods, reducing the risk of exposing exploitable functionality.

See the OWASP 最需要关注漏洞 section for more information about the protections built into the Odoo framework.

独立安全性审计

Odoo is regularly assessed by independent security companies engaged by our customers and prospects to conduct security audits and penetration tests. The Odoo Security Team reviews the findings and implements corrective measures where necessary.

We cannot disclose these assessment reports because they are confidential and belong to the organizations that commissioned them.

Odoo also works with an active community of independent security researchers who review our source code and help us continuously improve its security. Our security research and disclosure process is described on our 责任信息披露 页。

OWASP 最需要关注漏洞

The following summarizes how Odoo addresses common web application security risks identified by the 开放式Web应用程序安全项目 (OWASP)所列出的:

  • Injection Flaws: Injection flaws occur when untrusted data is passed to an interpreter as part of a command or query, potentially causing unintended commands to be executed or data to be modified.

    Odoo relies on an object-relational mapping (ORM) framework that abstracts query construction and prevents SQL injection by default. Developers do not normally need to construct SQL queries manually: queries are generated by the ORM and parameters are properly escaped.

  • Cross-Site Scripting (XSS): XSS vulnerabilities occur when untrusted content is included in a web page without appropriate escaping or encoding, potentially allowing an attacker to execute scripts in another user's browser.

    The Odoo framework escapes expressions rendered into views and pages by default, preventing XSS in normal usage. Developers must explicitly mark expressions as safe before they can be included as raw content in rendered pages.

  • Cross-Site Request Forgery (CSRF): A CSRF attack attempts to make an authenticated user's browser submit an unauthorized request to a web application using the user's existing session.

    The Odoo website engine includes built-in CSRF protection. HTTP controllers do not accept protected POST requests without the corresponding security token. The token is provided when the user legitimately accesses the relevant form and cannot be forged by an attacker.

  • Malicious File Execution: Remote file inclusion vulnerabilities can allow an attacker to load and execute hostile code or data on a server.

    Odoo does not expose functionality for remote file inclusion. Privileged users can customize certain features using expressions evaluated by the system, but these expressions run in a sandboxed and sanitized environment with access limited to permitted functions.

  • Insecure Direct Object Reference: Direct object references expose identifiers for internal objects, such as records or files. They become a vulnerability when manipulating those identifiers allows unauthorized access.

    Odoo access control is enforced independently of the user interface. Exposing references to internal objects in URLs therefore does not bypass authorization: every request must still pass through the data access validation layer.

  • Insecure Cryptographic Storage: Weak protection of stored credentials or sensitive data can expose users to unauthorized access, identity theft, and other forms of abuse.

    Odoo uses industry-standard secure password hashing (PBKDF2 + SHA-512 with key stretching by default) to protect stored user passwords. External authentication systems such as OIDC/OAuth can also be used to avoid storing user passwords locally.

  • Insecure Communications: Sensitive information may be exposed when applications fail to appropriately encrypt network communications.

    Odoo Cloud enforces HTTPS by default. For on-premise installations, we recommend running Odoo behind a web server that provides encryption and proxies requests to Odoo, such as Apache, Lighttpd, or nginx. The Odoo deployment guide includes a 安全检查清单 for securing public deployments.

  • Failure to Restrict URL Access: Applications may expose sensitive functionality when authorization is enforced only by hiding links or URLs from unauthorized users.

    Odoo does not rely on the user interface or hidden URLs for access control. Every request must pass through the data access validation layer, so manipulating or directly accessing a URL does not bypass authorization. Where a URL intentionally provides unauthenticated access to sensitive information, such as a customer order confirmation link, the URL is protected with a unique digitally signed token and sent only to the intended recipient.

报告安全漏洞

To report a security vulnerability, please use our 责任信息披露页面. Security reports are treated with high priority and assessed by the Odoo Security Team. We work with reporters to investigate and remediate confirmed issues and, where appropriate, disclose them responsibly to Odoo customers and users.

— Odoo 云端版(该平台)—备份/灾难修复数据库安全密码安全员工访问系统安全实体安全信用卡安全数据加密网络防御— Odoo(该软件)—软件安全安全始于设计独立安全性审计OWASP 最需要关注漏洞报告安全漏洞
社区
  • 教学视频
  • 文档
  • 论坛
开源
  • 下载
  • Github
  • Runbot
  • 翻译
服务
  • Odoo.sh 托管
  • 支持
  • 升级
  • 自定义开发服务
  • 教育
  • 查找会计服务
  • 寻找合作伙伴
  • 成为合作伙伴
关于我们
  • 我们的公司
  • 品牌资产
  • 联系我们
  • 招聘
  • 近期活动
  • 播客
  • 博客
  • 客户
  • 法律 • 隐私
  • 安全
الْعَرَبيّة Català 简体中文 繁體中文 (台灣) Čeština Dansk Nederlands English Suomi Français Deutsch हिंदी Bahasa Indonesia Italiano 日本語 한국어 (KR) Lietuvių kalba Język polski Português (BR) Português română русский язык Slovenský jazyk Slovenščina Español (América Latina) Español Svenska ภาษาไทย Türkçe українська Tiếng Việt

Odoo致力于为企业管理提供高效智能的开源解决方案,是全球业内高速成长的软件服务商之一,逾七百五十万用户选择Odoo进行数字化升级。通过一系列全业务链覆盖、高度集成、简单易用的商业应用,助力企业实现信息化改革、降本增效并释放公司增长潜力。

Odoo独特的价值在于是一款非常容易使用又完全集成的应用。

Website made with

Odoo Experience on YouTube

1. Use the live chat to ask your questions.
2. The operator answers within a few minutes.

Live support on Youtube
Watch now