Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3h3h-vg74-fvqw

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The module-description renderer in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier does not disable RST's local file inclusion, which allows privileged authenticated users to read local files via a crafted module description.

The module-description renderer in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier does not disable RST's local file inclusion, which allows privileged authenticated users to read local files via a crafted module description.

EPSS

Процентиль: 51%
0.00282
Низкий

Связанные уязвимости

CVSS3: 4.9
nvd
больше 6 лет назад

The module-description renderer in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier does not disable RST's local file inclusion, which allows privileged authenticated users to read local files via a crafted module description.

CVSS3: 4.9
debian
больше 6 лет назад

The module-description renderer in Odoo Community 11.0 and earlier and ...

EPSS

Процентиль: 51%
0.00282
Низкий