PT-2024-5990 · Apache · Apache Ofbiz
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache OFBiz versions prior to 18.12.16
Description
The issue is related to Server-Side Request Forgery (SSRF) and Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This vulnerability may allow a remote attacker to perform an SSRF attack. Over 2,700 results have been found to be potentially affected.
Recommendations
For Apache OFBiz versions prior to 18.12.16, upgrade to version 18.12.16, which fixes the issue. As a temporary workaround, consider restricting access to vulnerable components until a patch is applied. Avoid using URLs in files when loading them from Java or Groovy to prevent potential exploitation.
Exploit
Fix
RCE
Code Injection
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Ofbiz