Odoo Bulut (platformu)
CSA STAR Seviye 1
Odoo, CSA Güvenlik, Güven, Güvence ve Risk (STAR) Değerlendirmesi Programına katılır.
Konsensüs Değerlendirme Girişimi Anketi (CAIQ) v3.1'e verdiğimiz yanıtları görün
Yedekler / Acil Kurtarma
- We maintain a history of 14 full backups of each Odoo database for at least 3 months: daily backups for 7 days, weekly backups for 4 weeks, and monthly backups for 3 months.
- Backups replicated in at least 3 different data centers.
- Veri merkezlerimizin gerçek konumları şurada belirtilmiştir: Gizlilik Politikası sayfamız.
- Ayrıca kontrol panelini kullanarak istediğiniz zaman canlı verilerinizin manuel yedeklerini indirebilirsiniz.
- You can contact our Helpdesk to restore an available backup to your live database or to a separate database.
- Donanım arızasına karşı devreye alma: donanım arızası olasılığı bulunan bare metal sunucularda barındırılan servisler için, yerel hot standby replikasyonu uygulanır; bu sistem izleme ile desteklenir ve manuel bir devreye alma prosedürü ile çalışır
- Disaster recovery: we maintain disaster recovery procedures designed to restore Odoo Cloud services and customer data following major infrastructure failures or disasters. See our Cloud Service Level Agreement for more details and detailed Recovery Point Objectives (RPO) and Recovery Time Objectives (RTO).
Veri Tabanı Güvenliği
- Customer data is stored in a dedicated database and is not shared between customers.
- Data access controls isolate customer databases running on the same cluster, preventing access from one customer database to another.
Parola Güvenliği
- Customer passwords are protected using industry-standard PBKDF2+SHA512 password hashing, with salting and key stretching over thousands of rounds.
- Odoo staff cannot access or retrieve your password. If a password is lost, it must be reset.
- Oturum açma kimlik bilgileri her zaman HTTPS üzerinden güvenli bir şekilde iletilir.
- Customer database administrators can hız sınırlamayı yapılandırma and cooldown periods for repeated login attempts.
- Password policies: database administrators can enforce a minimum user password length. Other policies, such as required character classes, are not enabled by default because research has shown them to be counterproductive. See [Shay et al. 2016] and NIST SP 800-63b.
Çalışan Erişimi
- Odoo Helpdesk staff may access your account when necessary to investigate a support issue. They use dedicated staff credentials rather than your password, which they cannot access.
- Dedicated staff access allows our teams to reproduce reported issues without requiring you to share your password, while enabling staff actions to be separately controlled and audited.
- Helpdesk staff limit their access to the data, files, and settings necessary to diagnose and resolve your issue.
Sistem Güvenliği
- Tüm Odoo Bulut sunucuları, güncel güvenlik yamalarıyla güçlendirilmiş Linux dağıtımları üzerinde çalışmaktadır.
- Server installations are purpose-built and minimal, reducing the number of services that could introduce vulnerabilities.
- Remote server administration is restricted to a small number of trusted Odoo engineers and protected with personal multi-factor credentials.
Fiziksel Güvenlik
Odoo Cloud servers are hosted in trusted data centers across multiple regions. All hosting facilities must meet our physical security requirements, including:
- Restricted perimeters accessible only to authorized data center personnel.
- Physical access controls using security badges or biometric authentication.
- 24/7 security camera monitoring of data center facilities.
- 24/7 on-site security personnel.
Kredi Kartı Güvenliği
- We do not store credit card information on our systems.
- Credit card information is transmitted securely and directly to Çevresel Bileşen Ara Bağlantısı (PCI) ile Uyumlu payment acquirers. See our Gizlilik Politikası sayfamız for the list of providers.
Veri Şifreleme
Customer data is encrypted both in transit and at rest.- Communications with customer instances are protected using HTTPS with 256-bit SSL encryption.
- Internal communications between servers are protected with end-to-end encryption.
- Our servers are continuously monitored and kept up to date with patches for SSL vulnerabilities.
- Our SSL certificates use 2048-bit keys with full SHA-2 certificate chains. You can verify the SSL rating buradan.
- Customer data, including database contents and stored files, is encrypted at rest with AES-256 in both production systems and backups.
Ağ savunması
- Odoo Cloud için kullanılan veri merkezi sağlayıcıları, çoğu Hizmet Reddi saldırısı da dahil olmak üzere büyük hacimlere dayanacak şekilde tasarlanmış yüksek kapasiteli ağlar işletmektedir. Otomatik ve manuel önleme sistemleri, saldırı trafiğini hizmet kullanılabilirliğini kesintiye uğratmadan önce ağ sınırında tespit eder ve yönlendirir.
- Odoo Bulut sunucularındaki güvenlik duvarları ve saldırı önleme sistemleri, kaba kuvvet parola saldırıları gibi tehditlerin tespit edilmesine ve engellenmesine yardımcı olur.
- Customer database administrators can hız sınırlamayı yapılandırma ve tekrarlanan oturum açma denemeleri için bekleme süresini ayarlayın veya otomatik kaba kuvvet saldırılarını azaltmak için bir CAPTCHA yapılandırın.
Odoo (yazılım)
Yazılım Güvenliği
Odoo açık kaynaklıdır ve kod tabanının dünya çapındaki kullanıcılar ve katkıda bulunanlar tarafından sürekli olarak incelenmesine olanak tanır. Topluluk raporları, güvenlik geri bildiriminin önemli bir kaynağıdır; geliştiricileri ve güvenlik araştırmacılarını kodu denetlemeye ve güvenlik sorunlarını bildirmeye teşvik ediyoruz.
Odoo R&D processes include code reviews that consider security aspects for both new and contributed code.
Tasarımı gereği güvenli
The Odoo framework is designed to prevent common classes of security vulnerabilities by default:
- SQL injection is prevented by a higher-level API that generally removes the need for manually constructed SQL queries.
- Cross-site scripting (XSS) is prevented by a high-level templating system that automatically escapes injected data.
- The framework prevents RPC access to private methods, reducing the risk of exposing exploitable functionality.
See the OWASP Top Zafiyetleri section for more information about the protections built into the Odoo framework.
Bağımsız Güvenlik Denetimleri
Odoo is regularly assessed by independent security companies engaged by our customers and prospects to conduct security audits and penetration tests. The Odoo Security Team reviews the findings and implements corrective measures where necessary.
We cannot disclose these assessment reports because they are confidential and belong to the organizations that commissioned them.
Odoo also works with an active community of independent security researchers who review our source code and help us continuously improve its security. Our security research and disclosure process is described on our Sorumlu Bilgilendirme sayfa.
OWASP Top Zafiyetleri
The following summarizes how Odoo addresses common web application security risks identified by the Açık Web Uygulama Güvenliği Projesi (OWASP) (OWASP):
-
Injection Flaws: Injection flaws occur when untrusted data is passed to an interpreter as part of a command or query, potentially causing unintended commands to be executed or data to be modified.
Odoo, sorgu oluşturmayı soyutlayan ve varsayılan olarak SQL enjeksiyonunu önleyen bir nesne-ilişkisel eşleme (ORM) çerçevesine dayanır. Geliştiricilerin normalde SQL sorgularını manuel olarak oluşturmasına gerek yoktur: sorgular ORM tarafından oluşturulur ve parametreler uygun şekilde kaçırılır.
-
Cross-Site Scripting (XSS): XSS vulnerabilities occur when untrusted content is included in a web page without appropriate escaping or encoding, potentially allowing an attacker to execute scripts in another user's browser.
The Odoo framework escapes expressions rendered into views and pages by default, preventing XSS in normal usage. Developers must explicitly mark expressions as safe before they can be included as raw content in rendered pages.
-
Cross-Site Request Forgery (CSRF): A CSRF attack attempts to make an authenticated user's browser submit an unauthorized request to a web application using the user's existing session.
Odoo web sitesi motoru, yerleşik CSRF koruması içerir. HTTP denetleyicileri, ilgili güvenlik belirteci olmadan korumalı POST isteklerini kabul etmez. Belirteç, kullanıcı ilgili forma meşru bir şekilde eriştiğinde sağlanır ve bir saldırgan tarafından taklit edilemez.
-
Malicious File Execution: Remote file inclusion vulnerabilities can allow an attacker to load and execute hostile code or data on a server.
Odoo does not expose functionality for remote file inclusion. Privileged users can customize certain features using expressions evaluated by the system, but these expressions run in a sandboxed and sanitized environment with access limited to permitted functions.
-
Insecure Direct Object Reference: Direct object references expose identifiers for internal objects, such as records or files. They become a vulnerability when manipulating those identifiers allows unauthorized access.
Odoo access control is enforced independently of the user interface. Exposing references to internal objects in URLs therefore does not bypass authorization: every request must still pass through the data access validation layer.
-
Insecure Cryptographic Storage: Weak protection of stored credentials or sensitive data can expose users to unauthorized access, identity theft, and other forms of abuse.
Odoo uses industry-standard secure password hashing (PBKDF2 + SHA-512 with key stretching by default) to protect stored user passwords. External authentication systems such as OIDC/OAuth can also be used to avoid storing user passwords locally.
-
Insecure Communications: Sensitive information may be exposed when applications fail to appropriately encrypt network communications.
Odoo Cloud, varsayılan olarak HTTPS'yi zorunlu kılar. Yerinde kurulumlar için, Apache, Lighttpd veya nginx gibi şifreleme sağlayan ve Odoo'ya gelen istekleri proxy olarak yönlendiren bir web sunucusu arkasında Odoo'yu çalıştırmanızı öneririz. Odoo dağıtım kılavuzunda bir Güvenlik kontrol listesi for securing public deployments.
-
Failure to Restrict URL Access: Applications may expose sensitive functionality when authorization is enforced only by hiding links or URLs from unauthorized users.
Odoo, erişim kontrolü için kullanıcı arayüzüne veya gizli URL'lere güvenmez. Her istek, veri erişim doğrulama katmanından geçmek zorundadır; bu nedenle, bir URL'yi değiştirmek veya doğrudan erişmek, yetkilendirmeyi atlatmaz. Bir URL'nin, müşteri sipariş onayı bağlantısı gibi hassas bilgilere kasıtlı olarak kimlik doğrulaması yapılmamış erişim sağladığı durumlarda, söz konusu URL benzersiz bir dijital imzalı belirteçle korunur ve yalnızca hedeflenen alıcıya gönderilir.
Güvenlik Açıklarının Raporlanması
To report a security vulnerability, please use our sorumlu bilgilendirme sayfası. Security reports are treated with high priority and assessed by the Odoo Security Team. We work with reporters to investigate and remediate confirmed issues and, where appropriate, disclose them responsibly to Odoo customers and users.