CVE-2024-23946Path Traversal in Software Foundation Apache Ofbiz

Severity
5.3MEDIUMNVD
EPSS
2.7%
top 14.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 29

Description

Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to version 18.12.12, that fixes the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

NVDapache/ofbiz< 18.12.12

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hfjw-45j2-vgcx: Possible path traversal in Apache OFBiz allowing file inclusion2024-02-29
CVEList
Apache OFBiz: Path traversal or file inclusion2024-02-28

📋Vendor Advisories

1
Apache
Apache ofbiz: CVE-2024-23946
CVE-2024-23946 — Path Traversal | cvebase