CVE-2021-30128
published 2021-04-27CVE-2021-30128: Apache OFBiz has unsafe deserialization prior to 17.12.07 version
PriorityP187critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
81.08%
99.6th percentile
Apache OFBiz has unsafe deserialization prior to 17.12.07 version
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ofbiz | < 17.12.07 | 17.12.07 |
| apache | ofbiz | — | — |
| apache_software_foundation | apache_ofbiz | >= Apache OFBiz < 17.12.07 | 17.12.07 |
Detection & IOCsextracted from sources · hover to see the quote
sigma
matchers-condition: and matchers: - type: word part: interactsh_protocol words: - "dns" - type: word part: body words: - 'value="errorMessage"'
- →Exploit payload uses Java gadget with DNS callback via interactsh; detect out-of-band DNS interactions triggered from OFBiz server as evidence of successful deserialization exploitation.
- →Response body containing 'value="errorMessage"' combined with a DNS interaction from the target confirms the deserialization vulnerability is triggered.
- ·Vulnerability affects all Apache OFBiz releases before 17.12.07; upgrade to 17.12.07 or later to remediate. ↗
- ·The NVD description confirms the unsafe deserialization root cause; no version-specific patch bypass is noted beyond the 17.12.07 fix. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
vendor_apache9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7ffx-8mw5-5mgr: Apache OFBiz has unsafe deserialization prior to 17
ghsa_unreviewed·2022-05-24
CVE-2021-30128 [CRITICAL] CWE-502 GHSA-7ffx-8mw5-5mgr: Apache OFBiz has unsafe deserialization prior to 17
Apache OFBiz has unsafe deserialization prior to 17.12.07 version
VulnCheck
Apache OFBiz Deserialization of Untrusted Data
vulncheck·2021·CVSS 9.8
CVE-2021-30128 [CRITICAL] Apache OFBiz Deserialization of Untrusted Data
Apache OFBiz Deserialization of Untrusted Data
Apache OFBiz has unsafe deserialization prior to 17.12.07 version
Affected: Apache OFBiz
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://kevintel.com/CVE-2021-30128
Exploit PoC: https://vulncheck.com/xdb/5d3bec4dff54
Apache
Apache ofbiz: CVE-2021-30128
vendor_apache·CVSS 9.8
CVE-2021-30128 [CRITICAL] Apache ofbiz: CVE-2021-30128
Apache ofbiz: CVE-2021-30128
; affected all releases before 17.12.07; fixed in 17.12.07 with commits 643b9c7 a343812 62e657f fcc0078 3f97578 7fd9d05 .
No detection rules found.
Nuclei
Apache OFBiz <17.12.07 - Arbitrary Code Execution
nuclei·CVSS 9.8
CVE-2021-30128 [CRITICAL] Apache OFBiz <17.12.07 - Arbitrary Code Execution
Apache OFBiz
{{generate_java_gadget("dns", "https://{{interactsh-url}}", "hex")}}
matchers-condition: and
matchers:
- type: word
part: interactsh_protocol
words:
- "dns"
- type: word
part: body
words:
- 'value="errorMessage"'
# digest: 4a0a0047304502201929aff7577c9a9b599fbfcf22a637a8f5b64968027817643a933e785c6706d6022100a6f3f78a45415eded6758718f8e4ee71cd527ed3ab0f1f07e0ec08c95c8ce88c:922c64590222798bb761d5b6d8e72950
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2021/04/27/5https://lists.apache.org/thread.html/r078351a876ed284ba667b33aba29428d7308a5bd4df78f14a3df6661%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r108a964764b8bd21ebd32ccd4f51c183ee80a251c105b849154a8e9d%40%3Ccommits.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rab718cfe6468085d7560c0c1ae816841e175886199f42e36efb8d735%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rb3f5cd65f3ddce9b9eb4d6ea6e2919933f0f89b15953769d11003743%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/rb3f5cd65f3ddce9b9eb4d6ea6e2919933f0f89b15953769d11003743%40%3Cdev.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rb3f5cd65f3ddce9b9eb4d6ea6e2919933f0f89b15953769d11003743%40%3Cdev.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rb3f5cd65f3ddce9b9eb4d6ea6e2919933f0f89b15953769d11003743%40%3Cuser.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rb82f41de3c44bb644632531f79649046ca76afeab25a2bdb9991ab84%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rbe512e5ccd6b11169c6379daa1234bc805f3d53c5a38224e956295ce%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rbe8439b26a71fc3b429aa793c65dcc4a6e349bc7bb5010746a74fa1d%40%3Ccommits.ofbiz.apache.org%3Ehttp://www.openwall.com/lists/oss-security/2021/04/27/5https://lists.apache.org/thread.html/r078351a876ed284ba667b33aba29428d7308a5bd4df78f14a3df6661%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r108a964764b8bd21ebd32ccd4f51c183ee80a251c105b849154a8e9d%40%3Ccommits.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rab718cfe6468085d7560c0c1ae816841e175886199f42e36efb8d735%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rb3f5cd65f3ddce9b9eb4d6ea6e2919933f0f89b15953769d11003743%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/rb3f5cd65f3ddce9b9eb4d6ea6e2919933f0f89b15953769d11003743%40%3Cdev.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rb3f5cd65f3ddce9b9eb4d6ea6e2919933f0f89b15953769d11003743%40%3Cdev.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rb3f5cd65f3ddce9b9eb4d6ea6e2919933f0f89b15953769d11003743%40%3Cuser.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rb82f41de3c44bb644632531f79649046ca76afeab25a2bdb9991ab84%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rbe512e5ccd6b11169c6379daa1234bc805f3d53c5a38224e956295ce%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rbe8439b26a71fc3b429aa793c65dcc4a6e349bc7bb5010746a74fa1d%40%3Ccommits.ofbiz.apache.org%3E
2021-04-27
Published
Exploited in the wild