{ "id": "CVE-2018-14866", "sourceIdentifier": "cve@mitre.org", "published": "2019-07-03T18:15:10.317", "lastModified": "2020-08-24T17:37:01.140", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "Incorrect access control in the TransientModel framework in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated attackers to access data in transient records that they do not own by making an RPC call before garbage collection occurs." }, { "lang": "es", "value": "El control de acceso incorrecto en el marco de TransientModel en Odoo Community 11.0 y versiones anteriores y Odoo Enterprise 11.0 y versiones anteriores permite que los atacantes identificados accedan a datos en registros transitorios que no poseen al realizar una llamada RPC antes de que se produzca la recolecci\u00f3n de basura." } ], "metrics": { "cvssMetricV30": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 4.3, "baseSeverity": "MEDIUM" }, "exploitabilityScore": 2.8, "impactScore": 1.4 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N", "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "SINGLE", "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 4.0 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.0, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-732" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:odoo:odoo:9.0:*:*:*:community:*:*:*", "matchCriteriaId": "C3F9E8F1-FAF7-44AE-8D05-BE717D247EDE" }, { "vulnerable": true, "criteria": "cpe:2.3:a:odoo:odoo:9.0:*:*:*:enterprise:*:*:*", "matchCriteriaId": "167C709E-C8B2-4CCB-963E-E1D8C664190A" }, { "vulnerable": true, "criteria": "cpe:2.3:a:odoo:odoo:10.0:*:*:*:community:*:*:*", "matchCriteriaId": "C52F2EEB-11E5-49E8-AD06-3014FF2C2D24" }, { "vulnerable": true, "criteria": "cpe:2.3:a:odoo:odoo:10.0:*:*:*:enterprise:*:*:*", "matchCriteriaId": "A4405E54-6C16-49D5-B632-3D72091B2FEB" }, { "vulnerable": true, "criteria": "cpe:2.3:a:odoo:odoo:11.0:*:*:*:community:*:*:*", "matchCriteriaId": "38424B03-4121-4A79-8E4E-4CB4DCD3E4A5" }, { "vulnerable": true, "criteria": "cpe:2.3:a:odoo:odoo:11.0:*:*:*:enterprise:*:*:*", "matchCriteriaId": "1298CF62-A06E-48AD-8141-0541DE3F6381" } ] } ] } ], "references": [ { "url": "https://github.com/odoo/odoo/issues/32509", "source": "cve@mitre.org", "tags": [ "Patch", "Third Party Advisory" ] } ] }