← Back

CVE-2020-29396

nvd nist
Published: Dec 22, 2020Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3.6 or later, allows remote authenticated users to execute arbitrary code, leading to privilege escalation.

Affected (2)

Products: Odoo: Odoo
1 product
Odoo
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Odoo
From 11.0 to 13.0
From 11.0 to 13.0
Running on/withPlatform Versions
Python
Python
From 3.6.0

References (4)

Source: security@odoo.com
PatchThird Party Advisory
Source: security@odoo.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.