PT-2023-8030 · Apache · Apache Ofbiz

Yun Peng

+1

·

Published

2023-12-26

·

Updated

2024-01-04

·

CVE-2023-50968

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache OFBiz versions prior to 18.12.11
Description The issue is related to insufficient validation of incoming requests, allowing a remote attacker to perform a Server-Side Request Forgery (SSRF) attack by sending a specially crafted HTTP request. This can also lead to arbitrary file properties reading vulnerability when a user operates a URI call without proper authorizations. The same URI can be exploited to realize a SSRF attack without authorizations.
Recommendations For versions prior to 18.12.11, upgrade to version 18.12.11 to fix the issue. As a temporary workaround, consider restricting access to unauthorized URI calls to minimize the risk of exploitation. Avoid operating URI calls without proper authorizations until the issue is resolved.

Fix

SSRF

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2024-00007
CVE-2023-50968

Affected Products

Apache Ofbiz