CVE-2017-10804
CVE-2017-10804 is a critical-severity vulnerability in Odoo with a CVSS 3.x base score of 9.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-306.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- CVSS v2: 7.5
- EPSS exploit prediction: 3% (88th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-306
- Affected product: Odoo
- Published:
- Last modified:
Description
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameters containing 0x00 characters are truncated before reaching the database layer. This occurs because Psycopg 2.x before 2.6.3 is used.
Frequently asked questions
- What is CVE-2017-10804?
- In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameters containing 0x00 characters are truncated before reaching the database layer. This occurs because Psycopg 2.x before 2.6.3 is used.
- How severe is CVE-2017-10804?
- CVE-2017-10804 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2017-10804 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 3% (88th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2017-10804?
- CVE-2017-10804 primarily affects Odoo. In total, 5 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2017-10804?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2017-10804 published?
- CVE-2017-10804 was published on 2017-07-04 and last updated on 2026-06-17.
References
- http://initd.org/psycopg/docs/news.html#what-s-new-in-psycopg-2-6-3
- https://github.com/odoo/odoo/issues/17914
- https://github.com/psycopg/psycopg2/issues/420
Affected products (5)
- cpe:2.3:a:odoo:odoo:8.0:*:*:*:*:*:*:*
- cpe:2.3:a:odoo:odoo:9.0:*:*:*:community:*:*:*
- cpe:2.3:a:odoo:odoo:9.0:*:*:*:enterprise:*:*:*
- cpe:2.3:a:odoo:odoo:10.0:*:*:*:community:*:*:*
- cpe:2.3:a:odoo:odoo:10.0:*:*:*:enterprise:*:*:*
More vulnerabilities in Odoo
- CVE-2018-14885 — Critical (CVSS 9.8): Incorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and…
- CVE-2021-44547 — Critical (CVSS 9.1): A sandboxing issue in Odoo Community 15.0 and Odoo Enterprise 15.0 allows authenticated administrators to executed…
- CVE-2018-15632 — Critical (CVSS 9.1): Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and…
- CVE-2018-14860 — Critical (CVSS 9.1): Improper sanitization of dynamic user expressions in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and…
- CVE-2020-29396 — High (CVSS 8.8): A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python…
- CVE-2019-11781 — High (CVSS 8.8): Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier,…
Other CWE-306 (Missing Authentication for Critical Function) vulnerabilities
- CVE-2026-20357 — Critical (CVSS 10.0): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team…
- CVE-2026-58115 — Critical (CVSS 10.0): A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running…
- CVE-2026-63508 — Critical (CVSS 10.0): Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to…
- CVE-2026-56163 — Critical (CVSS 10.0): Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to…
- CVE-2026-64812 — Critical (CVSS 10.0): In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
- CVE-2026-60644 — Critical (CVSS 10.0): Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).…
Browse all CWE-306 (Missing Authentication for Critical Function) vulnerabilities →