Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-14886

Опубликовано: 28 июн. 2019
Источник: debian

Описание

The module-description renderer in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier does not disable RST's local file inclusion, which allows privileged authenticated users to read local files via a crafted module description.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
odoonot-affectedpackage

Примечания

  • https://github.com/odoo/odoo/issues/32513

Связанные уязвимости

CVSS3: 4.9
nvd
больше 6 лет назад

The module-description renderer in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier does not disable RST's local file inclusion, which allows privileged authenticated users to read local files via a crafted module description.

github
больше 3 лет назад

The module-description renderer in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier does not disable RST's local file inclusion, which allows privileged authenticated users to read local files via a crafted module description.