CVE-2017-10804 Information
Feb 14, 2021
cve
Description
In Odoo 8.0 Odoo Community Edition 9.0 and 10.0 and Odoo Enterprise Edition 9.0 and 10.0 remote attackers can bypass authentication under certain circumstances because parameters containing 0x00 characters are truncated before reaching the database layer. This occurs because Psycopg 2.x before 2.6.3 is used.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
http://initd.org/psycopg/docs/news.htmlwhat-s-new-in-psycopg-2-6-3 https://github.com/odoo/odoo/issues/17914 https://github.com/psycopg/psycopg2/issues/420
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: