CVE-2021-44476

NameCVE-2021-44476
DescriptionA sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read local files on the server, including sensitive configuration files.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-5399-1
Debian Bugs1035953

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
odoo (PTS)bullseye (security), bullseye14.0.0+dfsg.2-7+deb11u2fixed
sid17.0.0+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
odoosourcebullseye14.0.0+dfsg.2-7+deb11u1DSA-5399-1
odoosource(unstable)16.0.0+dfsg.1-11035953

Notes

https://github.com/odoo/odoo/issues/107684
14.0 patch at https://github.com/odoo/odoo/commit/be2c857a2e19b0a752555ab377ce5e1cb081a186

Search for package or bug name: Reporting problems