CVE-2018-14868

NameCVE-2018-14868
DescriptionIncorrect access control in the Password Encryption module in Odoo Community 9.0 and Odoo Enterprise 9.0 allows authenticated users to change the password of other users without knowing their current password via a crafted RPC call.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
odoo (PTS)bullseye (security), bullseye14.0.0+dfsg.2-7+deb11u2fixed
sid, trixie17.0.0+dfsg3-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
odoosource(unstable)(not affected)

Notes

- odoo <not-affected> (Fixed before initial upload to Debian)
https://github.com/odoo/odoo/issues/32507

Search for package or bug name: Reporting problems