In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymization data in the Database Anonymization module allows remote authenticated privileged users to execute arbitrary Python code, because unpickle is used.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/odoo/odoo/issues/17898 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2017-07-04T18:00:00
Updated: 2024-08-05T17:50:11.800Z
Reserved: 2017-07-03T00:00:00
Link: CVE-2017-10803
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-07-04T18:29:00.177
Modified: 2024-11-21T03:06:32.277
Link: CVE-2017-10803
Redhat
No data.