CVE-2021-23166

NameCVE-2021-23166
DescriptionA sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read and write local files on the server.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-5399-1
Debian Bugs1035953

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
odoo (PTS)bullseye (security), bullseye14.0.0+dfsg.2-7+deb11u1fixed
sid16.0.0+dfsg.2-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
odoosourcebullseye14.0.0+dfsg.2-7+deb11u1DSA-5399-1
odoosource(unstable)16.0.0+dfsg.1-11035953

Notes

https://github.com/odoo/odoo/issues/107687
14.0 patch at https://github.com/odoo/odoo/commit/1f1e03ff29f711dd26cfbcadc60b7d03fdb59ed7

Search for package or bug name: Reporting problems