Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-10804

Опубликовано: 04 июл. 2017
Источник: debian
EPSS Низкий

Описание

In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameters containing 0x00 characters are truncated before reaching the database layer. This occurs because Psycopg 2.x before 2.6.3 is used.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
odoonot-affectedpackage

Примечания

  • https://github.com/odoo/odoo/issues/17914

EPSS

Процентиль: 75%
0.00882
Низкий

Связанные уязвимости

CVSS3: 9.8
nvd
больше 8 лет назад

In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameters containing 0x00 characters are truncated before reaching the database layer. This occurs because Psycopg 2.x before 2.6.3 is used.

CVSS3: 9.8
github
больше 3 лет назад

In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameters containing 0x00 characters are truncated before reaching the database layer. This occurs because Psycopg 2.x before 2.6.3 is used.

EPSS

Процентиль: 75%
0.00882
Низкий