CVE-2024-36259
Last modified
CVE-2024-36259 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attackers to extract sensitive information via an oracle-based (yes/no response) crafted attack.. EPSS estimates a 0.63% chance of exploitation in the next 30 days.
Description
Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attackers to extract sensitive information via an oracle-based (yes/no response) crafted attack.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Odoo | Odoo | 17.0 |
References
- https://github.com/odoo/odoo/issues/199330Exploit, Mitigation, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-36259?
How severe is CVE-2024-36259?
How do I fix CVE-2024-36259?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-36252Improper restriction of communication channel to intended en…6.3
- CVE-2024-36253Uncontrolled search path in the Intel(R) SDP Tool for Window…7.8
- CVE-2024-36254Out-of-bounds read vulnerability exists in Sharp Corporation…7.5
- CVE-2024-36255Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x…5.7
- CVE-2024-36257Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using sha…5.3
- CVE-2024-36258A stack-based buffer overflow vulnerability exists in the to…9.8
- CVE-2024-3626The Email Subscribers by Icegram Express – Email Marketing, …4.3
- CVE-2024-36260in OpenHarmony v4.0.0 and prior versions allow a remote atta…9.8
- CVE-2024-36261Improper access control in Intel(R) RAID Web Console softwar…5.7
- CVE-2024-36262Race condition in some Intel(R) System Security Report and S…8.6
- CVE-2024-36263** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of S…8.1
- CVE-2024-36264** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vuln…9.8
Are you affected by CVE-2024-36259?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
