CVE-2024-25065

CWE-22Path Traversal4 documents4 sources
Severity
9.1CRITICAL
EPSS
0.8%
top 25.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 29

Description

Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages2 packages

NVDapache/ofbiz< 18.12.12

🔴Vulnerability Details

2
GHSA
GHSA-3vg3-g88w-vjgf: Possible path traversal in Apache OFBiz allowing authentication bypass2024-02-29
CVEList
Apache OFBiz: Path traversal allowing authentication bypass.2024-02-28

📋Vendor Advisories

1
Apache
Apache ofbiz: CVE-2024-25065
CVE-2024-25065 (CRITICAL CVSS 9.1) | Possible path traversal in Apache O | cvebase.io