{"api_version":"1","generated_at":"2026-07-23T10:22:27+00:00","cve":"CVE-2017-10804","urls":{"html":"https://cve.report/CVE-2017-10804","api":"https://cve.report/api/cve/CVE-2017-10804.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-10804","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-10804"},"summary":{"title":"CVE-2017-10804","description":"In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameters containing 0x00 characters are truncated before reaching the database layer. This occurs because Psycopg 2.x before 2.6.3 is used.","state":"PUBLISHED","assigner":"mitre","published_at":"2017-07-04 18:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-306","n/a"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://github.com/odoo/odoo/issues/17914","name":"https://github.com/odoo/odoo/issues/17914","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"],"title":"[SEC] ODOO-SA-2017-06-15-1 - Access control bypass via Psycopg2 vulnerability · Issue #17914 · odoo/odoo · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/psycopg/psycopg2/issues/420","name":"https://github.com/psycopg/psycopg2/issues/420","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"],"title":"Strings with NUL bytes are silently truncated in bound parameters · Issue #420 · psycopg/psycopg2 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://initd.org/psycopg/docs/news.html#what-s-new-in-psycopg-2-6-3","name":"http://initd.org/psycopg/docs/news.html#what-s-new-in-psycopg-2-6-3","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"Release notes — Psycopg 2.5.1.dev0 documentation","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-10804","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-10804","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"10804","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"odoo","cpe5":"odoo","cpe6":"10.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"community","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10804","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"odoo","cpe5":"odoo","cpe6":"10.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10804","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"odoo","cpe5":"odoo","cpe6":"8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10804","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"odoo","cpe5":"odoo","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"community","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10804","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"odoo","cpe5":"odoo","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T17:50:11.667Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/odoo/odoo/issues/17914"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://initd.org/psycopg/docs/news.html#what-s-new-in-psycopg-2-6-3"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/psycopg/psycopg2/issues/420"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2017-07-04T00:00:00.000Z","descriptions":[{"lang":"en","value":"In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameters containing 0x00 characters are truncated before reaching the database layer. This occurs because Psycopg 2.x before 2.6.3 is used."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-04T17:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/odoo/odoo/issues/17914"},{"tags":["x_refsource_CONFIRM"],"url":"http://initd.org/psycopg/docs/news.html#what-s-new-in-psycopg-2-6-3"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/psycopg/psycopg2/issues/420"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2017-10804","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameters containing 0x00 characters are truncated before reaching the database layer. This occurs because Psycopg 2.x before 2.6.3 is used."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://github.com/odoo/odoo/issues/17914","refsource":"CONFIRM","url":"https://github.com/odoo/odoo/issues/17914"},{"name":"http://initd.org/psycopg/docs/news.html#what-s-new-in-psycopg-2-6-3","refsource":"CONFIRM","url":"http://initd.org/psycopg/docs/news.html#what-s-new-in-psycopg-2-6-3"},{"name":"https://github.com/psycopg/psycopg2/issues/420","refsource":"CONFIRM","url":"https://github.com/psycopg/psycopg2/issues/420"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2017-10804","datePublished":"2017-07-04T18:00:00.000Z","dateReserved":"2017-07-03T00:00:00.000Z","dateUpdated":"2024-08-05T17:50:11.667Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-07-04 18:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-306","n/a"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:odoo:odoo:8.0:*:*:*:*:*:*:*","matchCriteriaId":"9D140CBF-E659-4E87-8FEE-F19CD2E6B947"},{"vulnerable":true,"criteria":"cpe:2.3:a:odoo:odoo:9.0:*:*:*:community:*:*:*","matchCriteriaId":"C3F9E8F1-FAF7-44AE-8D05-BE717D247EDE"},{"vulnerable":true,"criteria":"cpe:2.3:a:odoo:odoo:9.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"167C709E-C8B2-4CCB-963E-E1D8C664190A"},{"vulnerable":true,"criteria":"cpe:2.3:a:odoo:odoo:10.0:*:*:*:community:*:*:*","matchCriteriaId":"C52F2EEB-11E5-49E8-AD06-3014FF2C2D24"},{"vulnerable":true,"criteria":"cpe:2.3:a:odoo:odoo:10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"A4405E54-6C16-49D5-B632-3D72091B2FEB"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"10804","Ordinal":"1","Title":"CVE-2017-10804","CVE":"CVE-2017-10804","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"10804","Ordinal":"1","NoteData":"In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameters containing 0x00 characters are truncated before reaching the database layer. This occurs because Psycopg 2.x before 2.6.3 is used.","Type":"Description","Title":"CVE-2017-10804"},{"CveYear":"2017","CveId":"10804","Ordinal":"2","NoteData":"2017-07-04","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"10804","Ordinal":"3","NoteData":"2017-07-04","Type":"Other","Title":"Modified"}]}}}