CVE-2021-44465

Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows authenticated attackers to subscribe to receive future notifications and comments related to arbitrary business records in the system, via crafted RPC requests.
References
Link Resource
https://github.com/odoo/odoo/issues/107692 Issue Tracking Patch Vendor Advisory
https://github.com/odoo/odoo/issues/107692 Issue Tracking Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:odoo:odoo:*:*:*:*:community:*:*:*
cpe:2.3:a:odoo:odoo:*:*:*:*:enterprise:*:*:*

History

03 Feb 2025, 18:15

Type Values Removed Values Added
CWE CWE-863

21 Nov 2024, 06:31

Type Values Removed Values Added
References () https://github.com/odoo/odoo/issues/107692 - Issue Tracking, Patch, Vendor Advisory () https://github.com/odoo/odoo/issues/107692 - Issue Tracking, Patch, Vendor Advisory

15 Jul 2024, 02:15

Type Values Removed Values Added
CWE CWE-284

03 May 2023, 14:12

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
CPE cpe:2.3:a:odoo:odoo:*:*:*:*:community:*:*:*
cpe:2.3:a:odoo:odoo:*:*:*:*:enterprise:*:*:*
CWE NVD-CWE-noinfo
References (MISC) https://github.com/odoo/odoo/issues/107692 - (MISC) https://github.com/odoo/odoo/issues/107692 - Issue Tracking, Patch, Vendor Advisory

25 Apr 2023, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-25 19:15

Updated : 2025-02-03 18:15


NVD link : CVE-2021-44465

Mitre link : CVE-2021-44465

CVE.ORG link : CVE-2021-44465


JSON object : View

Products Affected

odoo

  • odoo
CWE
CWE-284

Improper Access Control

NVD-CWE-noinfo CWE-863

Incorrect Authorization