Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-53933 | Improper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user to export the OAuth tokens of other users. |
| Link | Providers |
|---|---|
| https://github.com/odoo/odoo/issues/193854 |
|
Tue, 25 Feb 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-116 |
Tue, 25 Feb 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Feb 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-116 |
Tue, 25 Feb 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-116 | CWE-284 |
Tue, 25 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user to export the OAuth tokens of other users. | |
| Weaknesses | CWE-116 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: odoo
Published:
Updated: 2025-02-25T18:59:46.305Z
Reserved: 2024-12-09T14:40:14.799Z
Link: CVE-2024-12368
Updated: 2025-02-25T18:59:40.741Z
Status : Received
Published: 2025-02-25T18:15:27.020
Modified: 2025-02-25T19:15:14.227
Link: CVE-2024-12368
No data.
OpenCVE Enrichment
No data.
EUVD