Headline
Debian Security Advisory 5399-1
Debian Linux Security Advisory 5399-1 - Several vulnerabilities were discovered in odoo, a suite of web based open source business apps.
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Debian Security Advisory DSA-5399-1 [email protected]
https://www.debian.org/security/ Sebastien Delafond
May 05, 2023 https://www.debian.org/security/faq
Package : odoo
CVE ID : CVE-2021-23166 CVE-2021-23176 CVE-2021-23178 CVE-2021-23186
CVE-2021-23203 CVE-2021-26263 CVE-2021-26947 CVE-2021-44476
CVE-2021-44775 CVE-2021-45071 CVE-2021-45111
Several vulnerabilities were discovered in odoo, a suite of web based
open source business apps.
CVE-2021-44775, CVE-2021-26947, CVE-2021-45071, CVE-2021-26263:
XSS allowing remote attacker to inject arbitrary commands.
CVE-2021-45111:
Incorrect access control allowing authenticated remote user to
create user accounts and access restricted data.
CVE-2021-44476, CVE-2021-23166:
Incorrect access control allowing authenticated remote administrator
to access local files on the server.
CVE-2021-23186:
Incorrect access control allowing authenticated remote administrator
to modify database contents of other tenants.
CVE-2021-23178:
Incorrect access control allowing authenticated remote user to
use another user’s payment method.
CVE-2021-23176:
Incorrect access control allowing authenticated remote user to
access accounting information.
CVE-2021-23203:
Incorrect access control allowing authenticated remote user to
access arbitrary documents via PDF exports.
For the stable distribution (bullseye), these problems have been fixed in
version 14.0.0+dfsg.2-7+deb11u1.
We recommend that you upgrade your odoo packages.
For the detailed security status of odoo please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/odoo
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----
iQEzBAEBCgAdFiEEAqSkbVtrXP4xJMh3EL6Jg/PVnWQFAmRU7kEACgkQEL6Jg/PV
nWTQrAf+K6CpxmFeKM/7G70xafsw+lLu4UlaoLYUh55rgsFd9/YHUuwCHiCmoP1P
4GnVJkNu6qj8rW1EReUtKZ76XQTLsD9ZxgM6tFBGA9EDi0hPjR4KEI7jtdXjx9ro
8LOyu51xeqoraKTmkPw+EnUCWCjutH78l8y9ywqHORQI0WM9Q2Zh0fHJz1c+2uzd
HqFvo1brOgu7zkI3luH8IjEHpCHpUVbe8rTnY0g2PSrZott/k0fIZ8qNSzyfG7ah
R5auoI5y+z5TusByKWnQ48jQCbU8WeqXaQUqT/pGtjGz9ljClTwDkmqqv/6BNnyF
Et5uV+Yn6UWsxXUcz6u9CwOzkrpVxA==
=KDFV
-----END PGP SIGNATURE-----
Related news
Improper access control in reporting engine of l10n_fr_fec module in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to extract accounting information via crafted RPC packets.
Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments with a tokenized payment method that belongs to another user, causing the victim's payment method to be charged instead.
A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to access and modify database contents of other tenants, in a multi-tenant system.
Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to download PDF reports for arbitrary documents, via crafted requests.
Cross-site scripting (XSS) issue in Discuss app of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to inject arbitrary web script in the browser of a victim, by posting crafted contents.
Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, via a crafted link.
A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read local files on the server, including sensitive configuration files.
Cross-site scripting (XSS) issue in Website app of Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, by posting crafted contents.
Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, via crafted uploaded file names.
Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to trigger the creation of demonstration data, including user accounts with known credentials.
A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read and write local files on the server.