BIT-odoo-2020-29396

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/odoo/BIT-odoo-2020-29396.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-odoo-2020-29396
Aliases
Published
2024-03-06T11:01:56.602Z
Modified
2025-04-03T14:40:37.652Z
Summary
[none]
Details

A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3.6 or later, allows remote authenticated users to execute arbitrary code, leading to privilege escalation.

Database specific
{
    "cpes": [
        "cpe:2.3:a:odoo:odoo:*:*:*:*:community:*:*:*",
        "cpe:2.3:a:odoo:odoo:*:*:*:*:enterprise:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / odoo

Package

Name
odoo
Purl
pkg:bitnami/odoo

Severity

  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
11.0.0
Fixed
13.0.1

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/odoo/BIT-odoo-2020-29396.json"