Name | CVE-2018-15632 |
Description | Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to initialize an empty database on which they can connect with default credentials. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Vulnerable and fixed packages
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|
odoo (PTS) | bullseye (security), bullseye | 14.0.0+dfsg.2-7+deb11u2 | fixed |
| sid, trixie | 17.0.0+dfsg3-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|
odoo | source | (unstable) | (not affected) | | | |
Notes
- odoo <not-affected> (Fixed before initial upload to Debian)
https://github.com/odoo/odoo/issues/63700