CVE-2021-29200
published 2021-04-27CVE-2021-29200: Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack
critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ofbiz | < 17.12.07 | 17.12.07 |
| apache | ofbiz | — | — |
| apache_software_foundation | apache_ofbiz | >= Apache OFBiz < 17.12.07 | 17.12.07 |