CVE-2024-25065
published 2024-02-29CVE-2024-25065: Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.
PriorityP275critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
47.67%
98.7th percentile
Possible path traversal in Apache OFBiz allowing authentication bypass.
Users are recommended to upgrade to version 18.12.12, that fixes the issue.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ofbiz | < 18.12.12 | 18.12.12 |
| apache | ofbiz | — | — |
| apache_software_foundation | apache_ofbiz | < 18.12.12 | 18.12.12 |
Detection & IOCsextracted from sources · hover to see the quote
- →Path traversal vulnerability in Apache OFBiz can be used to bypass authentication; monitor HTTP requests to OFBiz endpoints for path traversal patterns (e.g., sequences like `..;/`, `%2e%2e`, or similar encoded traversal strings) that may reach protected resources without valid credentials. ↗
- →Apache OFBiz versions before 18.12.12 are vulnerable; identify and prioritize patching any internet-exposed OFBiz instances running versions prior to 18.12.12. ↗
- ·The fix was introduced in Apache OFBiz 18.12.12 via a specific commit; verify the exact commit is present if running a custom or patched build rather than relying solely on version number. ↗
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_apache9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apache
Apache ofbiz: CVE-2024-25065
vendor_apache·CVSS 9.1
CVE-2024-25065 [CRITICAL] Apache ofbiz: CVE-2024-25065
Apache ofbiz: CVE-2024-25065
; affected releases before 18.12.12; fixed in 18.12.12 with commit b91a9b7f26
GHSA
GHSA-3vg3-g88w-vjgf: Possible path traversal in Apache OFBiz allowing authentication bypass
ghsa_unreviewed·2024-02-29
CVE-2024-25065 [CRITICAL] CWE-22 GHSA-3vg3-g88w-vjgf: Possible path traversal in Apache OFBiz allowing authentication bypass
Possible path traversal in Apache OFBiz allowing authentication bypass.
Users are recommended to upgrade to version 18.12.12, that fixes the issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2024/02/28/10https://issues.apache.org/jira/browse/OFBIZ-12887https://lists.apache.org/thread/rplfjp7ppn9ro49oo7jsrpj99m113lfchttps://ofbiz.apache.org/download.htmlhttps://ofbiz.apache.org/release-notes-18.12.12.htmlhttps://ofbiz.apache.org/security.htmlhttp://www.openwall.com/lists/oss-security/2024/02/28/10https://issues.apache.org/jira/browse/OFBIZ-12887https://lists.apache.org/thread/rplfjp7ppn9ro49oo7jsrpj99m113lfchttps://ofbiz.apache.org/download.htmlhttps://ofbiz.apache.org/release-notes-18.12.12.htmlhttps://ofbiz.apache.org/security.html
2024-02-29
Published