cbcvebase.
CVE-2019-12425
published 2020-04-30

CVE-2019-12425: Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host

high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host

Affected

3 ranges
VendorProductVersion rangeFixed in
apacheapache_ofbiz
apacheofbiz
apacheofbiz