Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-14865

Опубликовано: 03 июл. 2019
Источник: debian
EPSS Низкий

Описание

Report engine in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier does not use secure options when passing documents to wkhtmltopdf, which allows remote attackers to read local files.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
odoonot-affectedpackage

Примечания

  • https://github.com/odoo/odoo/issues/32501

EPSS

Процентиль: 45%
0.00225
Низкий

Связанные уязвимости

CVSS3: 6.5
nvd
больше 6 лет назад

Report engine in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier does not use secure options when passing documents to wkhtmltopdf, which allows remote attackers to read local files.

CVSS3: 6.5
github
больше 3 лет назад

Report engine in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier does not use secure options when passing documents to wkhtmltopdf, which allows remote attackers to read local files.

EPSS

Процентиль: 45%
0.00225
Низкий