Back to overview

CVE-2020-29396

CRITICAL
9.9
CVSS 3.0
Description
A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3.6 or later, allows remote authenticated users to execute arbitrary code, leading to privilege escalation.

Metadata

CVE ID
CVE-2020-29396
State
PUBLISHED
Assigner
odoo
Reserved
2020-11-30 00:00 UTC
Published
2020-12-22 16:25 UTC
Last updated
2024-08-04 16:55 UTC
Primary CWE
CWE-267
CWE-267: Privilege Defined With Unsafe Actions
Vendor / Product
Odoo / Odoo Community
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Affected products (4)
VendorProductPlatformVersions
Odoo Odoo Community 11.0 < unspecified
Odoo Odoo Community unspecified ≤ 13.0
Odoo Odoo Enterprise 11.0 < unspecified
Odoo Odoo Enterprise unspecified ≤ 13.0
Weakness (CWE)
CWESourceDescription
CWE-267 cna CWE-267: Privilege Defined With Unsafe Actions
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.0 cna CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Back to overview