PT-2024-5990 · Apache · Apache Ofbiz

·

CVE-2024-45507

·

Published

2024-08-14

·

Updated

2026-01-02

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache OFBiz versions prior to 18.12.16
Description The issue is related to Server-Side Request Forgery (SSRF) and Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This vulnerability may allow a remote attacker to perform an SSRF attack. Over 2,700 results have been found to be potentially affected.
Recommendations For Apache OFBiz versions prior to 18.12.16, upgrade to version 18.12.16, which fixes the issue. As a temporary workaround, consider restricting access to vulnerable components until a patch is applied. Avoid using URLs in files when loading them from Java or Groovy to prevent potential exploitation.

Exploit

Fix

RCE

Code Injection

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-06799
CVE-2024-45507

Affected Products

Apache Ofbiz