-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 28 Apr 2023 06:28:07 +0200 Source: odoo Binary: odoo-14 Architecture: source all Version: 14.0.0+dfsg.3-1~bpo11+2 Distribution: bullseye-backports Urgency: high Maintainer: Freexian Packaging Team <team+freexian@tracker.debian.org> Changed-By: Sebastien Delafond <seb@debian.org> Description: odoo-14 - Open Source Apps To Grow Your Business Changes: odoo (14.0.0+dfsg.3-1~bpo11+2) bullseye-backports; urgency=high . * debian/patches: fix recent CVEs CVE-2021-44775, CVE-2021-26947, CVE-2021-26263: XSS allowing remote attacker to inject arbitrary commands. CVE-2021-45111: Incorrect access control allowing authenticated remote user to create user accounts and access restricted data. CVE-2021-44476, CVE-2021-23166: Incorrect access control allowing authenticated remote administrator to access local files on the server. CVE-2021-23186: Incorrect access control allowing authenticated remote administrator to modify database contents of other tenants. CVE-2021-23178: Incorrect access control allowing authenticated remote user to use another user's payment method. CVE-2021-23176: Incorrect access control allowing authenticated remote user to access accounting information. CVE-2021-23203: Incorrect access control allowing authenticated remote user to access arbitrary documents via PDF exports. Checksums-Sha1: 5d344e0881b237aea91e4cac03d3ef287ca6a0a3 1653 odoo_14.0.0+dfsg.3-1~bpo11+2.dsc 3a599bf9e8a16bf1c364ee85abe65cfb79586a03 34068 odoo_14.0.0+dfsg.3-1~bpo11+2.debian.tar.xz da5870c80eeda033b69896161443998991672b4b 72447460 odoo-14_14.0.0+dfsg.3-1~bpo11+2_all.deb 6ec4755e8437932a08d70c6b71ec20731ce46e55 6421 odoo_14.0.0+dfsg.3-1~bpo11+2_amd64.buildinfo Checksums-Sha256: da951874b1cb6e9fed01051e95b740d908253cead8a6f8e8d5bb72382e6a54e9 1653 odoo_14.0.0+dfsg.3-1~bpo11+2.dsc 564b6182bbbbb66ec838e13e1f95fe610d4cb132df6bceb0687b13a353f8198f 34068 odoo_14.0.0+dfsg.3-1~bpo11+2.debian.tar.xz 84558f5495c77675f45a20d245024676d83dcace9cf049ec270b47b2df67abf5 72447460 odoo-14_14.0.0+dfsg.3-1~bpo11+2_all.deb 12133d7bca90cdf3284e8d2578d0523d63078b2a37e9e7f3111976ebb263efe2 6421 odoo_14.0.0+dfsg.3-1~bpo11+2_amd64.buildinfo Files: 77e427a28b2ddd8ad4edcd657ac0e04c 1653 net optional odoo_14.0.0+dfsg.3-1~bpo11+2.dsc 1a4e4203346038d2b3206d2820692d31 34068 net optional odoo_14.0.0+dfsg.3-1~bpo11+2.debian.tar.xz 475045de0df718af33897b79eba3fe2c 72447460 net optional odoo-14_14.0.0+dfsg.3-1~bpo11+2_all.deb 6b5fee1999cd92e037e456b6a3838223 6421 net optional odoo_14.0.0+dfsg.3-1~bpo11+2_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEEAqSkbVtrXP4xJMh3EL6Jg/PVnWQFAmRU+98ACgkQEL6Jg/PV nWQSewf/ZEUZ6xOt39Z9HmSG3bqaL16CB/mHcJxsBD4XKUZH8OmcOjc7r4YJeUoi 3LHc2Dx9/Y++eFWeiNi+Xpgg9+yR6t02vS9EJIdgFYsBvlrON781nHrVFj5W5mR4 wPg5kGt6a2aiji+8/RX3ci3E4j/+P+H55QzgGf83jy73JI4Trx14Eks2X8so8AeQ rNOkoWiLsiEAiz6u5Q3byPvZgsGDo4IoiF24qr5JU72EwJ6T39w3I4M0N2ldIELf al3AgjPs4WxAF35Baf+tvDSSFZUW2QFL7GwxlXPxZf+++daNGvZHBnN/lFwFKFuU hJQpO6D6d9TTUwj3n6Wsf5FTDlJuZg== =v9lu -----END PGP SIGNATURE-----