PT-2019-11418 · Apache · Apache Ofbiz

Niels Heinen

·

Publicado

2019-09-11

·

Atualizado

2021-07-21

·

CVE-2019-10074

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Apache OFBiz versions prior to 16.11.06
Description: A remote code execution (RCE) issue is possible when Freemarker markup is entered in a textarea field of an Apache OFBiz Form Widget, specifically when encoding has been disabled on such a field. This was identified in the Customer Request "story" input within the Order Manager application. It is advised that encoding should not be disabled without a valid reason, especially within fields that accept user input.
Recommendations: For versions prior to 16.11.06, upgrade to 16.11.06 or manually apply the commit r1858533 on branch 16.11 as a mitigation measure.

Correção

RCE

Special Elements Injection

Improper Encoding or Escaping of Output

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-10074

Produtos afetados

Apache Ofbiz