A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to access and modify database contents of other tenants, in a multi-tenant system.
A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.
Link | Tags |
---|---|
https://github.com/odoo/odoo/issues/107688 | issue tracking patch vendor advisory |
https://www.debian.org/security/2023/dsa-5399 |