cbcvebase.
CVE-2021-37608
published 2021-08-18

CVE-2021-37608: Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apache OFBiz…

PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
6.03%
92.6th percentile
Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apache OFBiz version 17.12.07 and prior versions. Upgrade to at least 17.12.08 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12297.

Affected

3 ranges
VendorProductVersion rangeFixed in
apacheofbiz< 17.12.0817.12.08
apacheofbiz
apache_software_foundationapache_ofbizunspecified – 17.12.07

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability involves unrestricted upload of a file with a dangerous type (e.g., web shell) in Apache OFBiz, enabling remote code execution. Monitor for unexpected file uploads to OFBiz endpoints.
  • All Apache OFBiz releases before 17.12.08 are affected. Detect vulnerable versions in use via banner or version fingerprinting.
  • ·The fix was introduced in Apache OFBiz 17.12.08. Systems running 17.12.07 or earlier are vulnerable. Patch reference commit is 8d49af4.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_apache9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.