In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymization data in the Database Anonymization module allows remote authenticated privileged users to execute arbitrary Python code, because unpickle is used.
References
Link Resource
https://github.com/odoo/odoo/issues/17898 Patch Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2017-07-04T18:00:00

Updated: 2017-07-04T17:57:01

Reserved: 2017-07-03T00:00:00


Link: CVE-2017-10803

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2017-07-04T18:29:00.177

Modified: 2019-10-03T00:03:26.223


Link: CVE-2017-10803

JSON object: View

cve-icon Redhat Information

No data.

CWE