CVE-2024-36259Improper Access Control in Odoo

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 75.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 25

Description

Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attackers to extract sensitive information via an oracle-based (yes/no response) crafted attack.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

CVEListV5odoo/odoo_communitymaster17.0
CVEListV5odoo/odoo_enterprisemaster17.0
debiandebian/odoo< odoo 18.0.0+dfsg-1 (sid)
NVDodoo/odoo17.0

🔴Vulnerability Details

2
OSV
CVE-2024-36259: Improper access control in mail module of Odoo Community 172025-02-25
GHSA
GHSA-x3g3-3qwm-w95x: Improper access control in mail module of Odoo Community 172025-02-25

📋Vendor Advisories

1
Debian
CVE-2024-36259: odoo - Improper access control in mail module of Odoo Community 17.0 and Odoo Enterpris...2024