Friday, October 24, 2025
1 change · saas-18.2
Security fixes and vulnerability patches
This fixes an access control gap in Expenses that could let users change approved expense sheets when they should not be allowed to. The update enforces permission checks more consistently, helping protect approved expense data from unauthorized changes.
Original PR description
The state changes right check was only done on specific method but it wasn't check at write level. Which allowed to bypass it. The record rule on hr_expense_user without a check on the state is in draft allow to change data on approved expense sheets. forward port : #189360 Forward-Port-Of: odoo/odoo#216850