216.73.217.22

CVE-2024-12368

· Published 25/02/2025 18:15 · Modified 28/02/2025 15:40

Labels: CVE-2024-12368 2025-02-25CVE-2024-12368CWE-116CWE-284NVD-CWE-noinfo[email protected]

Essential information

Published
25/02/2025 18:15
Modified
28/02/2025 15:40
Author
Creator
CVSS
8.1 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CVSS metrics

Description

Improper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user to export the OAuth tokens of other users.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
odoo / odoo cpe:2.3:a:odoo:odoo:15.0:*:*:*:community:*:*:*
odoo / odoo cpe:2.3:a:odoo:odoo:15.0:*:*:*:enterprise:*:*:*

References