Vulnerability Description
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameters containing 0x00 characters are truncated before reaching the database layer. This occurs because Psycopg 2.x before 2.6.3 is used.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Odoo | Odoo | 8.0 |
Related Weaknesses (CWE)
References
- http://initd.org/psycopg/docs/news.html#what-s-new-in-psycopg-2-6-3Release Notes
- https://github.com/odoo/odoo/issues/17914PatchThird Party Advisory
- https://github.com/psycopg/psycopg2/issues/420ExploitThird Party Advisory
- http://initd.org/psycopg/docs/news.html#what-s-new-in-psycopg-2-6-3Release Notes
- https://github.com/odoo/odoo/issues/17914PatchThird Party Advisory
- https://github.com/psycopg/psycopg2/issues/420ExploitThird Party Advisory
FAQ
What is CVE-2017-10804?
CVE-2017-10804 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameters containing 0x00 ch...
How severe is CVE-2017-10804?
CVE-2017-10804 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-10804?
Check the references section above for vendor advisories and patch information. Affected products include: Odoo Odoo.