⚠ Actively exploited
Added to CISA KEV on 2024-08-07. Federal agencies required to patch by 2024-08-28. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable..

CVE-2024-32113

CWE-22Path Traversal12 documents11 sources
Severity
9.8CRITICAL
EPSS
94.0%
top 0.11%
CISA KEV
KEV
Added 2024-08-07
Due 2024-08-28
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedMay 8
KEV addedAug 7
KEV dueAug 28
Latest updateOct 1
CISA Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDapache/ofbiz< 18.12.13

Patches

🔴Vulnerability Details

3
GHSA
GHSA-38cv-ch3v-j5cw: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz2024-05-08
CVEList
Apache OFBiz: Path traversal leading to RCE2024-05-08
VulnCheck
Apache OFBiz Path Traversal Vulnerability2024

💥Exploits & PoCs

4
Exploit-DB
Apache OFBiz 18.12.12 - Directory Traversal2024-05-19
Nuclei
Apache OFBiz - Improper Authorization & Remote Code Execution
Metasploit
Apache OFBiz forgotPassword/ProgramExport RCE
Nuclei
Apache OFBiz Directory Traversal - Remote Code Execution

🔍Detection Rules

1
Suricata
ET WEB_SPECIFIC_APPS Apache OFBiz Remote Code Execution via Path Confusion (CVE-2024-32113)2024-10-01

📋Vendor Advisories

2
CISA
Apache OFBiz Path Traversal Vulnerability2024-08-07
Apache
Apache ofbiz: CVE-2024-32113
CVE-2024-32113 (CRITICAL CVSS 9.8) | Improper Limitation of a Pathname t | cvebase.io