CVE-2017-10803 describes a critical vulnerability in Odoo Community Edition (versions 8.0, 9.0, 10.0) and Odoo Enterprise Edition (versions 9.0, 10.0), specifically within the Database Anonymization module. This flaw allows remote authenticated privileged users to execute arbitrary Python code due to the insecure use of unpickle. With a CVSS score of 6.5 (MEDIUM), successful exploitation grants high impact on confidentiality, integrity, and availability, requiring local access and user interaction. While not listed in CISA's KEV catalog, an exploit (EDB-44064) is publicly available, though there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0CPE matchmatch criteria | cpe:2.3:a:odoo:odoo:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:a:odoo:odoo:9.0:*:*:*:community:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:a:odoo:odoo:9.0:*:*:*:enterprise:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:a:odoo:odoo:10.0:*:*:*:community:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:a:odoo:odoo:10.0:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.