PT-2023-8030 · Apache · Apache Ofbiz

Yun Peng

+1

·

Publicado

2023-12-26

·

Atualizado

2024-01-04

·

CVE-2023-50968

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache OFBiz versions prior to 18.12.11
Description The issue is related to insufficient validation of incoming requests, allowing a remote attacker to perform a Server-Side Request Forgery (SSRF) attack by sending a specially crafted HTTP request. This can also lead to arbitrary file properties reading vulnerability when a user operates a URI call without proper authorizations. The same URI can be exploited to realize a SSRF attack without authorizations.
Recommendations For versions prior to 18.12.11, upgrade to version 18.12.11 to fix the issue. As a temporary workaround, consider restricting access to unauthorized URI calls to minimize the risk of exploitation. Avoid operating URI calls without proper authorizations until the issue is resolved.

Correção

SSRF

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-00007
CVE-2023-50968

Produtos afetados

Apache Ofbiz