PT-2022-19419 · Apache · Apache Ofbiz

Joseph Farebrother

+1

·

Published

2022-09-02

·

Updated

2023-07-21

·

CVE-2022-29158

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache OFBiz versions prior to 18.12.06
Description The issue arises from the way Apache OFBiz handles URLs provided by external, unauthenticated users, making it vulnerable to Regular Expression Denial of Service (ReDoS).
Recommendations For versions prior to 18.12.06, upgrade to 18.12.06 or apply the necessary patches to resolve the issue.

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2022-29158

Affected Products

Apache Ofbiz