Monday, October 27, 2025
1 change · saas-18.3
Security fixes and vulnerability patches
This update prevents employees from changing approved expense sheets by bypassing normal permission checks. It strengthens control over expense approvals so finalized records remain protected from unauthorized edits.
Original PR description
The state changes right check was only done on specific method but it wasn't check at write level. Which allowed to bypass it. The record rule on hr_expense_user without a check on the state is in draft allow to change data on approved expense sheets. forward port : #189360 Forward-Port-Of: odoo/odoo#217203 Forward-Port-Of: odoo/odoo#216850