Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 18.12.17.
Users are recommended to upgrade to version 18.12.17, which fixes the issue.
Metrics
Affected Vendors & Products
References
History
Fri, 22 Nov 2024 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Tue, 19 Nov 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Mon, 18 Nov 2024 09:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.17. Users are recommended to upgrade to version 18.12.17, which fixes the issue. | |
Title | Apache OFBiz: URLs allowing remote use of Groovy expressions, leading to RCE | |
Weaknesses | CWE-918 CWE-94 |
|
References |
|
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2024-11-18T08:43:17.743Z
Updated: 2024-11-19T14:59:02.765Z
Reserved: 2024-09-21T11:29:47.639Z
Link: CVE-2024-47208
Vulnrichment
Updated: 2024-11-18T09:03:46.416Z
NVD
Status : Awaiting Analysis
Published: 2024-11-18T09:15:06.100
Modified: 2024-11-21T09:39:31.100
Link: CVE-2024-47208
Redhat
No data.