CVE-2017-10803

MEDIUM

Odoo - Insecure Deserialization

Title source: rule
STIX 2.1

Description

In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymization data in the Database Anonymization module allows remote authenticated privileged users to execute arbitrary Python code, because unpickle is used.

Exploits (1)

exploitdb WORKING POC
by SecuriTeam · locallinux
https://www.exploit-db.com/exploits/44064

References (1)

Core 1
Core References
Patch, Third Party Advisory x_refsource_confirm
https://github.com/odoo/odoo/issues/17898

Scores

CVSS v3 6.5
EPSS 0.0155
EPSS Percentile 81.5%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-502
Status published
Products (3)
odoo/odoo 8.0
odoo/odoo 9.0 (2 CPE variants)
odoo/odoo 10.0 (2 CPE variants)
Published Jul 04, 2017
Tracked Since Feb 18, 2026