-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 28 Apr 2023 06:28:07 +0200 Source: odoo Binary: odoo-14 Architecture: all Version: 14.0.0+dfsg.2-7+deb11u1 Distribution: bullseye-security Urgency: high Maintainer: all Build Daemon (x86-grnet-02) Changed-By: Sebastien Delafond Description: odoo-14 - Open Source Apps To Grow Your Business Changes: odoo (14.0.0+dfsg.2-7+deb11u1) stable-security; urgency=high . * debian/patches: fix recent CVEs CVE-2021-44775, CVE-2021-26947, CVE-2021-45071, CVE-2021-26263: XSS allowing remote attacker to inject arbitrary commands. CVE-2021-45111: Incorrect access control allowing authenticated remote user to create user accounts and access restricted data. CVE-2021-44476, CVE-2021-23166: Incorrect access control allowing authenticated remote administrator to access local files on the server. CVE-2021-23186: Incorrect access control allowing authenticated remote administrator to modify database contents of other tenants. CVE-2021-23178: Incorrect access control allowing authenticated remote user to use another user's payment method. CVE-2021-23176: Incorrect access control allowing authenticated remote user to access accounting information. CVE-2021-23203: Incorrect access control allowing authenticated remote user to access arbitrary documents via PDF exports. Checksums-Sha1: 463592d5f1c5d2dcd6381834939d2ecfa76ef4ed 67766560 odoo-14_14.0.0+dfsg.2-7+deb11u1_all.deb 57420e281a95a6844cababd945d6452941d65c49 6498 odoo_14.0.0+dfsg.2-7+deb11u1_all-buildd.buildinfo Checksums-Sha256: 7bac741849a5efe818de5734965861d9606998204337ca0ea9e6bbc3e6db68a7 67766560 odoo-14_14.0.0+dfsg.2-7+deb11u1_all.deb 45ad83fe776502cbc45d279ce11a2aa435d161f637da289501aebea16da10dc9 6498 odoo_14.0.0+dfsg.2-7+deb11u1_all-buildd.buildinfo Files: a75d3d6b3652857dd5b2e963c7a3cc9c 67766560 net optional odoo-14_14.0.0+dfsg.2-7+deb11u1_all.deb 6c89390b9fb21f5d16f715b0b152a141 6498 net optional odoo_14.0.0+dfsg.2-7+deb11u1_all-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEzW1K1578DQd6MDTQEbLkkg2OS0oFAmRUxnsACgkQEbLkkg2O S0oclhAAiVuBgw6KXgDxTFlpqhGbniR9xrzjq/iWBIxhh+jCJhYFzRDOfVq0Wjzg rMnadO0aoAkxC1lLm9Af6ihJPNednWjE3VAnzoK6fAk6JmXQbqIkd+5bFVx7/HUC LMqF9er7KMlr12FVAYzbE14kC30/AeeJwiMge2UGrCm3SEv4xe46Y0zo6YnuUBdQ IpRvzY/zRfEgbfBn0g4aYX5XcmyHeWNBQB4VguxVvR6b9j+8GiMhbZsf1vvsY1f9 nLCcRnaawVrCZzr1EI+aT5cYErMpfhZ/tQk8nmvb6u7t8nK3osfJ4XLl1Tlc0wPq +8/Z1ThTP2EtGZSBmy6+jvxnjQQnYqaRS0IXifFg8W3cJZli4R89+DvKVBMOQJeU 6r/6AliYAELX5Ue8Vif9GaOEC9HXuTFBz0zygUVCyCMQAZynq8t1kFDrvHpRDlIU otihl5fPZaE+i2stqGnn/ZGVMd+2m+OWMSj/1K42V7Bsp+ngNi4/yZCB7HPA48Wp NCSwRTyv1YNZYH3oKBAnS7RqBJcKDRivda0xETF9ys23JdtxG8gocM/BiUFY7t/k /lCD8MVp0HWIDrXJwE7Tlyt/SlSCy+qWOonIq1ed+7Ht2VP06I6oog5r3Nlu0fz6 ck0veBy4Q9TwrGACFXnrR/ITxQRHoRZ/IzbNIQB+A2K2i6PbaUw= =lS/I -----END PGP SIGNATURE-----