Files
odoo_source/SECURITY.md
T
Victor Feyens cbe1e8e5a5 [FIX] github core: deprecate 12.0
closes odoo/odoo#77923

X-original-commit: 986efb96eee7f1caeeb335bc8d63cd4643d80f54
Related: odoo/enterprise#21494
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
Signed-off-by: Victor Feyens (vfe) <vfe@odoo.com>
2021-10-07 17:59:53 +00:00

1.7 KiB

Security Policy

Supported Versions

Version Supported
15.0 ✅
14.0 ✅
13.0 ✅
<=12.0 ❌

Reporting a Vulnerability

Please share privately the details of your security vulnerability by contacting our Security Team: Contact Info

Make sure to include as much information as possible, with the detailed steps to reproduce the problem, the versions that are affected, the expected results and actual results, and any other information that might help us react faster and more efficiently.

We tend to prefer text-based descriptions accompanied with a proof-of-concept script/exploit, rather than screenshots and videos.

Our Responsible Disclosure page gives an overview of the process, including:

  • Our Incident Response Procedure (what will happen after you report an issue)
  • Our Rules (what you can and cannot do while researching security issues)
  • Guidelines with DO REPORT and DO NOT REPORT issues (what kind of issues will be accepted/rejected)

Important note

We receive a majority of security reports that have little to no impact on the security of Odoo or the Odoo Cloud, and we ultimately have to reject them. To avoid a disappointing experience when contacting us, please try to put together a proof-of-concept attack and take a critical look at what's really at risk. If the proposed attack scenario turns out unrealistic, your report will probably be rejected. Also be sure to review our list of non-qualifying issues.