CVE-2022-25371
published 2022-09-02CVE-2022-25371: Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in Birt…
PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.06%
89.5th percentile
Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id=538142) it is possible to perform a remote code execution (RCE) attack in Apache OFBiz, release 18.12.05 and earlier.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ofbiz | < 18.12.06 | 18.12.06 |
| apache | ofbiz | — | — |
| apache_software_foundation | apache_ofbiz | Apache OFBiz – 18.12.05 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Apache OFBiz RCE via Birt plugin; versions 18.12.05 and earlier are vulnerable (CVE-2022-25371). The fix was introduced in version 18.12.08 with commit 41ff12cf8 — detect exploitation attempts targeting Birt report/data-visualization endpoints on OFBiz instances running 18.12.07 or earlier. ↗
- ·CVE-2022-25371 affects Apache OFBiz release 18.12.05 and earlier (NVD) / 18.12.07 (Apache security page); the fix is in 18.12.08 (commit 41ff12cf8). The two sources cite different affected versions — ensure your asset inventory checks both 18.12.05 and 18.12.07 as potentially vulnerable. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_apache9.8CRITICAL
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4vm3-cxh9-9697: Apache OFBiz uses the Birt project plugin (https://eclipse
ghsa_unreviewed·2022-09-03
CVE-2022-25371 [CRITICAL] CWE-22 GHSA-4vm3-cxh9-9697: Apache OFBiz uses the Birt project plugin (https://eclipse
Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id=538142) it is possible to perform a remote code execution (RCE) attack in Apache OFBiz, release 18.12.05 and earlier.
Red Hat
kernel: ext4: fix race condition between ext4_write and ext4_convert_inline_data
vendor_redhat·2025-02-26·CVSS 4.7
CVE-2022-49414 [MEDIUM] CWE-362 kernel: ext4: fix race condition between ext4_write and ext4_convert_inline_data
kernel: ext4: fix race condition between ext4_write and ext4_convert_inline_data
In the Linux kernel, the following vulnerability has been resolved:
ext4: fix race condition between ext4_write and ext4_convert_inline_data
Hulk Robot reported a BUG_ON:
EXT4-fs error (device loop3): ext4_mb_generate_buddy:805: group 0,
block bitmap and bg descriptor inconsistent: 25 vs 31513 free clusters
kernel BUG at fs/ext4/ext4_jbd2.c:53!
invalid opcode: 0000 [#1] SMP KASAN PTI
CPU: 0 PID: 25371 Comm: syz-executor.3 Not tainted 5.10.0+ #1
RIP: 0010:ext4_put_nojournal fs/ext4/ext4_jbd2.c:53 [inline]
RIP: 0010:__ext4_journal_stop+0x10e/0x110 fs/ext4/ext4_jbd2.c:116
[...]
Call Trace:
ext4_write_inline_data_end+0x59a/0x730 fs/ext4/inline.c:795
generic_perform_write+0x279/0x3c0 mm/filemap.c:3344
ext4_buffere
Apache
Apache ofbiz: CVE-2022-25371
vendor_apache·CVSS 9.8
CVE-2022-25371 [CRITICAL] Apache ofbiz: CVE-2022-25371
Apache ofbiz: CVE-2022-25371
; affected release 18.12.07; fixed in 18.12.08 with commit 41ff12cf8
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2022/09/02/7http://www.openwall.com/lists/oss-security/2022/09/03/1http://www.openwall.com/lists/oss-security/2022/09/08/2https://lists.apache.org/thread/bvp3sczqq863lxr1wh7wjvdtjbkcwspqhttp://www.openwall.com/lists/oss-security/2022/09/02/7http://www.openwall.com/lists/oss-security/2022/09/03/1http://www.openwall.com/lists/oss-security/2022/09/08/2https://lists.apache.org/thread/bvp3sczqq863lxr1wh7wjvdtjbkcwspq
2022-09-02
Published