CVE-2017-10804
Dashboard / Vulnerabilities / CVE-2017-10804
CVE-2017-10804
Published: 4 Jul 2017Last Modified: 10 Mar 2026
Summary:
Details: In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameters containing 0x00 characters are truncated before reaching the database layer. This occurs because Psycopg 2.x before 2.6.3 is used.
References: , http://initd.org/psycopg/docs/news.html#what-s-new-in-psycopg-2-6-3, https://github.com/odoo/odoo/issues/17914, https://github.com/psycopg/psycopg2/issues/420
Affected packages
Package
Name:
Purl:
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
