Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-12368

Опубликовано: 25 фев. 2025
Источник: debian
EPSS Низкий

Описание

Improper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user to export the OAuth tokens of other users.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
odoofixed16.0.0+dfsg.1-1package
odooend-of-lifebullseyepackage

Примечания

  • https://github.com/odoo/odoo/issues/193854

EPSS

Процентиль: 49%
0.00668
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 1 года назад

Improper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user to export the OAuth tokens of other users.

CVSS3: 8.1
nvd
больше 1 года назад

Improper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user to export the OAuth tokens of other users.

CVSS3: 8.1
github
больше 1 года назад

Improper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user to export the OAuth tokens of other users.

CVSS3: 8.1
fstec
больше 1 года назад

Уязвимость CRM-системы Odoo Community Edition и ERP-системы Odoo Enterprise Edition, связанная с недостатками контроля доступа, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 49%
0.00668
Низкий