Skip to Content

Contributors

Re: [PSA] mail template editor group, mass mailing user group

I think a security repository sounds like a great idea. I am less enthusiastic about auto-installation, as its use is a bit contentious and has spawned modules like module_change_auto_install.

On Thu, Feb 29, 2024 at 11:52 AM Holger Brunn <notifications@odoo-community.org> wrote:
> Did you report this vulnerability to Odoo SA?


> https://www.odoo.com/security-report [1]

yes, but I learned this was a choice they made. You're supposed to click the 
'restrict mail templates' flag in the general settings if you disagree. (which 
still doesn't change the fact that everyone is a mail template editor as soon 
as you install mass_mailing)

Seems a different philosophy, I want secure by default, they want easy. 
Actually, I was a bit frightened about this being a conscious choice so now 
I'm sifting through other core modules if I find similar choices.

If so, a secure-by-default oca repo might be in order, where we collect 
modules like the ones I propose above, and set them to auto install.



-- 
Your partner for the hard Odoo problems
https://hunki-enterprises.com

_______________________________________________
Mailing-List: https://odoo-community.org/groups/contributors-15
Post to: mailto:contributors@odoo-community.org
Unsubscribe: https://odoo-community.org/groups?unsubscribe


by "Adam Heinz" <adam.heinz@metricwise.com> - 07:16 - 29 Feb 2024

Reference

  • [PSA] mail template editor group, mass mailing user group
    Hi all,
    
    today I got aware that Odoo by default (and by design) assigns the mail 
    template editor group to all backend users. Sounds harmless, but being a 
    member of this group allows you to run code, and when you can run code you can 
    do all kinds of nefarious things in the database.
    
    Given I'm busy with Odoo for a very long time, I'm a little ashamed that this 
    is news for me, but as a few colleagues I asked were also not aware of this, 
    it seems a good idea to me to spread awareness.
    
    On https://github.com/OCA/social/pull/1319 you find a module that helps you 
    removing this potentially dangerous group from your users.
    
    A very similar issue is mass_mailing with the mass mailing user group, the 
    above PR also contains a module to address that.
    
    My (and my customers') expectation is: Nobody can run code unless being added 
    to some high privilege group like mass mailing user explicitly, and those 
    modules help implementing this.
    
    Best regards,
    Holger
    
    
    -- 
    Your partner for the hard Odoo problems
    https://hunki-enterprises.com

    by Holger Brunn - 04:41 - 29 Feb 2024