CVE-2018-14866

Incorrect access control in the TransientModel framework in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated attackers to access data in transient records that they do not own by making an RPC call before garbage collection occurs.
References
Link Resource
https://github.com/odoo/odoo/issues/32509 Patch Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:odoo:odoo:9.0:*:*:*:community:*:*:*
cpe:2.3:a:odoo:odoo:9.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:odoo:odoo:10.0:*:*:*:community:*:*:*
cpe:2.3:a:odoo:odoo:10.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:odoo:odoo:11.0:*:*:*:community:*:*:*
cpe:2.3:a:odoo:odoo:11.0:*:*:*:enterprise:*:*:*

History

No history.

Information

Published : 2019-07-03 18:15

Updated : 2023-12-10 12:59


NVD link : CVE-2018-14866

Mitre link : CVE-2018-14866

CVE.ORG link : CVE-2018-14866


JSON object : View

Products Affected

odoo

  • odoo
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource