PT-2024-8600 · Apache · Apache Ofbiz

孙相

·

Published

2024-11-16

·

Updated

2024-11-22

·

CVE-2024-47208

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache OFBiz versions prior to 18.12.17
Description The issue is related to Server-Side Request Forgery (SSRF) and Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This vulnerability may allow a remote attacker to perform an SSRF attack. Users are recommended to upgrade to a fixed version to resolve the issue.
Recommendations For Apache OFBiz versions prior to 18.12.17, upgrade to version 18.12.17, which fixes the issue. As a temporary workaround, consider restricting access to vulnerable components until a patch is applied.

Fix

SSRF

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2024-10169
CVE-2024-47208

Affected Products

Apache Ofbiz