VulnerabilityModified
CVE-2021-23203
Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to download PDF reports for arbitrary documents, via crafted requests.
HIGH 7.5EPSS 0.88%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.88%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to download PDF reports for arbitrary documents, via crafted requests.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.88% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284, CWE-863
- Affected
- odoo/odoo
- Source
- security@odoo.com
References
- https://github.com/odoo/odoo/issues/107695Issue Tracking, Patch, Vendor Advisory
- https://www.debian.org/security/2023/dsa-5399
- https://github.com/odoo/odoo/issues/107695Issue Tracking, Patch, Vendor Advisory
- https://www.debian.org/security/2023/dsa-5399
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.