The safety of Odoo systems is very important to us (not only because we use Odoo internally), and we consider security problems with the highest priority. We do our best every day to protect Odoo users from known security threats, and we welcome all reports of security vulnerabilities discovered by our users and contributors.
We are committed to handle vulnerability reports with the greatest attention, provided that the following rules are respected.
Please share privately the details of your security vulnerability by emailing our Security Team at . Make sure to include as much information as possible, including the detailed steps to reproduce the problem, the versions that are affected, the expected results and actual results, and any other information that might help us react faster and more efficiently. We tend to prefer text-based bug descriptions accompanied with a proof-of-concept script/exploit, rather than long videos. Our GPG Key 4096R/8E877D2F
Fingerprint: 9083 DE46 54A7 8DE3 CFAD D880 0B9E A35A 8E87 7D2F
Download: keys.openpgp.org
Download: (mirror) Reporting vulnerabilities via third-party websites is not acceptable, as it breaches the terms of our policy. If you are looking for a third-party reward, we may forward the list of CVE IDs assigned to you, so they can verify your rewards - but the issues have to be reported to us directly. Please note: we receive a majority of security reports that have little to no impact on the security of Odoo or Odoo Online, and we ultimately have to reject them. To avoid a disappointing experience when contacting us, please try to put together a proof-of-concept attack and take a critical look at what's really at risk. If the proposed attack scenario turns out unrealistic, your report will probably be rejected. Also be sure to review our list of non-qualifying issues below.
You may send this report from an anonymous email account, although we promise not to disclose your identity if you do not want us to.
You can also encrypt and verify messages to/from our security team with the GPG key linked above.
We ask you to observe the following rules at all times:
In return:
Self-XSS attacks requiring the user to actively copy/paste malicious code into their own browser window
"XSS attacks" by admins, e.g. via file uploads (SVG, HTML, JS, ...) or script injection. Administrators are webmasters, security restrictions don't apply to them, this is a feature.
Missing or partial verification of email addresses, or ways to circumvent it
Disclosure of public information or information that does not carry significant risks (directory listing on our downloads archive is a required feature! ;-))
If you have any doubt, please ask us first!
If you report a new security issue that is confirmed to be critical (see the DO REPORT section), we will publicly thank you by adding your name to the Odoo Security Hall of Fame, on the right of this page.
We are extremely grateful to the following security researchers who have worked with us to further improve the security of Odoo and the Odoo Cloud platforms!
Researcher | Année |
---|---|
Nils Hamerlinck (Trobz) | 2021, 2020, 2019, 2018, 2017, 2016 |
Colin Newell | 2017, 2016, 2015 |
IBS Group | 2019, 2018, 2017, 2015 |
Naglis Jonaitis | 2018, 2017, 2016, 2015 |
Swapnesh Shah | 2019, 2018 |
Ondřej Kuzník | 2017, 2016, 2015 |
lebr0nli (Alan Li) | 2024 |
Elliot Ward | 2024, 2023 |
Florent Mirieu de Labarre | 2019, 2018 |
Alexandre Moens | 2023, 2021 |
iamsushi | 2021, 2019 |
Rafi Shapiro | 2023 |
Alexandre Díaz | 2021, 2020 |
Yenthe Van Ginneken | 2019, 2018 |
Bhavin Fadadu | 2023 |
Niyas Raphy | 2022 |
Rifat Al Jubayer | 2022 |
Andreas Perhab (WT-IO-IT GmbH) | 2021 |
Parth Gajjar | 2021 |
Theodoros Malachias | 2021 |
Ranjit Pahan | 2021 |
Iago Ruiz | 2021 |
Johannes Moritz (Cure53) | 2021 |
Moez Hemani | 2021 |
Loc Truong | 2020 |
Damien LESCOS | 2020 |
Santosh Kumar Sha | 2020 |
Kennedy Sanchez | 2020 |
Abhiram V | 2020 |
Christopher Riis Bubeck Eriksen | 2020 |
"Raspina Net Pars Group" | 2020 |
Alessandro Innocenti | 2020 |
Holger Brunn (Hunki Enterprises BV) | 2019 |
Agustín Ezequiel Maio | 2019 |
Emre Övünç | 2019 |
Lauri Vakkala (Silverskin) | 2019 |
P. Valov (SoCyber) | 2019 |
Nathanael ROTA (Capgemini) | 2019 |
Tomas Canzoniero | 2019 |
Subash SN (Appsecco) | 2019 |
Bharath Kumar (Appsecco) | 2019 |
Dipanshu Agrawal | 2019 |
Anıl Yüksel | 2019 |
Aitor Fuentes (kr0no) | 2019 |
Erwin van der Ploeg (Odoo Experts) | 2018 |
Benoît Chenal (Excellium-services – Application Security) | 2018 |
Adan Álvarez (A2secure) | 2018 |
Bharath Kumar (Appsecco) | 2018 |
Subash SN (Appsecco) | 2018 |
Stéphane Bidoul (ACSONE) | 2018 |
Mehmet Tuncer | 2018 |
Hugo Rodrigues | 2018 |
Moises Lopez | 2018 |
Carlos Daudén,Tecnativa S.L. | 2018 |
Andrew Grasso (Logic Supply) | 2017 |
Juba Baghdad | 2017 |
Prakash Dhatti | 2017 |
JubaBaghdad | 2017 |
Romain E Silva (Sysdream) | 2017 |
Adel Nettar (Sysdream) | 2017 |
Azizul Hakim | 2017 |
"Ayrx" via SSD | 2017 |
Wolfgang Taferner(WT-IO-IT GmbH) | 2017 |
Corben Leo | 2017 |
Cameron Dawe | 2016 |
Xavier Alt | 2016 |
Vibhuti Ranjan Vidyarshy Nath | 2016 |
Mohammad Alhashash | 2016 |
Nagaraju Repala | 2016 |
Leonardo Pistone (Camptocamp France) | 2015 |
Mohamed Khaled Fathy | 2015 |
Dipak Kumar Das | 2015 |
Paul Catinean | 2015 |
Muhammed Gamal Fahmy | 2015 |
Openinside Co. | 2015 |
ONESTEiN / Glasswall | 2015 |
Sven Schleier, KPMG Management Consulting, SG | 2015 |
Ondřej Kuzník & Craig Gowing, credativ Ltd | 2015 |
Daniel Lawson | 2014 |
"diesenfranz" | 2014 |
Vo Minh Thu | 2013 |
Bastian Ike | 2013 |
The Security Team would also like to thank the following individuals for their contributions to improve the security of Odoo users (in alphabetical order): Aaron Devaney, Abhishek Venkat, Ahsan Khan, Ameya Darshan, Caleb Kinney, Cédric Krier, Christophe Hanon, Deepali Malekar, Fazal Ur Rahman, Flo van der Vlist, Huzaifa Jawaid, Ismail Tasdelen, Ivan Yelizariev, Jairo Llopis, Khan Janny, Leonardo "LeartS" Donelli, Mohammed Israil, Mohamed Karara, Niyas Raphy, Riccardo Ancarani, Saddam Maniyar, Sameer Phad, Sébastien Versailles, "St00rm N00b", Suyog Palav, Tarun Manhor- Abhaychandra Chede, Tayler Porter, Ye Yint Min Thu Htut, Ziaur Rashid
This program crawled on the 2015-09-08 is sorted as bounty.
FireBounty © 2015-2024