CVE-2021-44460

Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows users with deactivated accounts to access the system with the deactivated account and any permission it still holds, via crafted RPC requests.
References
Link Resource
https://github.com/odoo/odoo/issues/107685 Issue Tracking Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:odoo:odoo:*:*:*:*:community:*:*:*
cpe:2.3:a:odoo:odoo:*:*:*:*:enterprise:*:*:*

History

02 May 2023, 19:51

Type Values Removed Values Added
References (MISC) https://github.com/odoo/odoo/issues/107685 - (MISC) https://github.com/odoo/odoo/issues/107685 - Issue Tracking, Patch, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:odoo:odoo:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:odoo:odoo:*:*:*:*:community:*:*:*
First Time Odoo
Odoo odoo
CWE NVD-CWE-noinfo

25 Apr 2023, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-25 19:15

Updated : 2023-12-10 15:01


NVD link : CVE-2021-44460

Mitre link : CVE-2021-44460

CVE.ORG link : CVE-2021-44460


JSON object : View

Products Affected

odoo

  • odoo