Security issue: SQL injection

Bug #422563 reported by Cédric Krier
342
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Odoo Server (MOVED TO GITHUB)
Fix Released
Critical
Unassigned

Bug Description

I found a security hole in OpenERP that allows anybody with a login access to
retrieve/change/delete any data in the system.
I have an exploit script that retrieve or modify the admin password as proof
of concept.
The exploit works with XML-RPC, NET-RPC and also on eTiny and has been there
since at least version 3.4.2 (I could not check previous versions because the
source are no longer available).

I have written a patch that fix the hole.

Revision history for this message
Cédric Krier (cedk) wrote :
Revision history for this message
Cédric Krier (cedk) wrote :
Revision history for this message
Jay Vora (Serpent Consulting Services) (jayvora) wrote :

Hello Cédric Krier,

Fixed the hole by revision 1853 <email address hidden>.

Thank you very much.

Changed in openobject-server:
importance: Undecided → Critical
status: New → Fix Released
Revision history for this message
Cédric Krier (cedk) wrote :

I suggest you to request a CVE identifier for this issue and others.

Revision history for this message
Cédric Krier (cedk) wrote :

I changed the status because there is not yet any release with the security fix.

Changed in openobject-server:
status: Fix Released → Fix Committed
Changed in openobject-server:
status: Fix Committed → Fix Released
Revision history for this message
Cédric Krier (cedk) wrote :

And what about CVE identifier?

Cédric Krier (cedk)
visibility: private → public
visibility: public → private
Cédric Krier (cedk)
visibility: private → public
description: updated
visibility: public → private
Cédric Krier (cedk)
visibility: private → public
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Patches

Bug attachments

Remote bug watches

Bug watches keep track of this bug in other bug trackers.