CVE-2021-45111
8.1
HIGH
CVSS 3.1
EPSS 0.14%
Description
Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to trigger the creation of demonstration data, including user accounts with known credentials.
How to fix CVE-2021-45111
To remediate CVE-2021-45111, upgrade the affected package to a fixed version below.
- Bitnami/odoo—upgrade to 15.0.1 or later
- Debian/odoo—upgrade to 14.0.0+dfsg.2-7+deb11u1 or later
Is CVE-2021-45111 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 15.0.1
- from 0, < 14.0.0+dfsg.2-7+deb11u1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.1 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |