Thursday, September 17, 2026
2 changes · 18.0
Security fixes and vulnerability patches
This update closes a privacy gap that allowed employee referrers to download attachments from job applicants they were not authorized to view. Applicant files are now only shown when the current user has proper access, helping protect sensitive recruitment information.
Original PR description
Issue: ---------------------------------------- A referrer could open and download the attachments of an applicant they referred without any right to see that applicant's. Steps to reproduce:…
Issue: ---------------------------------------- A referrer could open and download the attachments of an applicant they referred without any right to see that applicant's. Steps to reproduce: ---------------------------------------- - Install hr_recruitment and hr_referral - Create two applicants for the same job position - Make another user the interviewer of the first one and the referrer of the second - Add an attachment to the second user - Connect as this user - In recruitment, go to the job position page - Click on the attachment button at the top - The user can download the attachment even though they can't access the applicant because they aren't their interviewer Cause: ---------------------------------------- The rule `hr_applicant_referral_user_rule` gives a referrer read access to the `hr.applicant` record they referred, so we can show them a few safe fields (`partner_name`, `job_id`, etc.). But they cannot see the applicant because of the field `is_accessible_to_current_user` added in `hr_referral` to prevent access to non interviewer users. `action_open_attachments` lists attachments of every application on the job from `application_ids`, without checking `is_accessible_to_current_user`, so it leaks attachments of applications the current user can only access as a referrer. Solution: ---------------------------------------- Create `_get_attachments_domain()` which will check `is_accessible_to_current_user` with an override in `hr_referral`. opw-6446049 Forward-Port-Of: odoo/odoo#283547
This update closes a privacy gap where employee referrers could download attachments from applicants they were not allowed to view. Job-position attachment lists now only show files linked to applicants the user is permitted to access, helping protect candidate information.
Original PR description
Issue: ---------------------------------------- A referrer could open and download the attachments of an applicant they referred without any right to see that applicant's. Steps to reproduce:…
Issue: ---------------------------------------- A referrer could open and download the attachments of an applicant they referred without any right to see that applicant's. Steps to reproduce: ---------------------------------------- - Install hr_recruitment and hr_referral - Create two applicants for the same job position - Make another user the interviewer of the first one and the referrer of the second - Add an attachment to the second user - Connect as this user - In recruitment, go to the job position page - Click on the attachment button at the top - The user can download the attachment even though they can't access the applicant because they aren't their interviewer Cause: ---------------------------------------- The rule `hr_applicant_referral_user_rule` gives a referrer read access to the `hr.applicant` record they referred, so we can show them a few safe fields (`partner_name`, `job_id`, etc.). But they cannot see the applicant because of the field `is_accessible_to_current_user` added in `hr_referral` to prevent access to non interviewer users. `action_open_attachments` lists attachments of every application on the job from `application_ids`, without checking `is_accessible_to_current_user`, so it leaks attachments of applications the current user can only access as a referrer. Solution: ---------------------------------------- Create `_get_attachments_domain()` which will check `is_accessible_to_current_user` with an override in `hr_referral`. opw-6446049 Forward-Port-Of: odoo/enterprise#128597