6.5

CVE-2018-14865

Report engine in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier does not use secure options when passing documents to wkhtmltopdf, which allows remote attackers to read local files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OdooOdoo Version9.0 SwEditioncommunity
OdooOdoo Version9.0 SwEditionenterprise
OdooOdoo Version10.0 SwEditioncommunity
OdooOdoo Version10.0 SwEditionenterprise
OdooOdoo Version11.0 SwEditioncommunity
OdooOdoo Version11.0 SwEditionenterprise
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.53% 0.715
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://github.com/odoo/odoo/issues/32501
Patch
Third Party Advisory