Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).
Severity
7.5HIGH
EPSS
83.9%
top 0.70%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedDec 26

Description

Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations. The same uri can be operated to realize a SSRF attack also without authorizations. Users are recommended to upgrade to version 18.12.11, which fixes this issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDapache/ofbiz< 18.12.11

Patches

🔴Vulnerability Details

3
GHSA
GHSA-gm45-8hgv-xg5f: Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations2023-12-26
CVEList
Apache OFBiz: Arbitrary file properties reading and SSRF attack2023-12-26
VulnCheck
Apache OFBiz Exposure of Sensitive Information to an Unauthorized Actor2023

💥Exploits & PoCs

1
Nuclei
Apache OFBiz < 18.12.11 - Server Side Request Forgery

📋Vendor Advisories

1
Apache
Apache ofbiz: CVE-2023-50968
CVE-2023-50968 (HIGH CVSS 7.5) | Arbitrary file properties reading v | cvebase.io