CVE-2021-45111

NameCVE-2021-45111
DescriptionImproper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to trigger the creation of demonstration data, including user accounts with known credentials.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-5399-1
Debian Bugs1035953

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
odoo (PTS)bullseye (security), bullseye14.0.0+dfsg.2-7+deb11u2fixed
sid, trixie17.0.0+dfsg3-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
odoosourcebullseye14.0.0+dfsg.2-7+deb11u1DSA-5399-1
odoosource(unstable)16.0.0+dfsg.1-11035953

Notes

https://github.com/odoo/odoo/issues/107683
14.0 patch at https://github.com/odoo/odoo/commit/d326153e016f93c22f40ad8fb146bb4108bb94dc

Search for package or bug name: Reporting problems