CVE-2025-54466
published 2025-08-15CVE-2025-54466: Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Apache…
PriorityP270critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
14.95%
96.4th percentile
Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin.
This issue affects Apache OFBiz: before 24.09.02 only when the scrum plugin is used.
Even unauthenticated attackers can exploit this vulnerability.
Users are recommended to upgrade to version 24.09.02, which fixes the issue.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ofbiz | < 24.09.02 | 24.09.02 |
| apache | ofbiz | — | — |
| apache_software_foundation | apache_ofbiz | < 24.09.02 | 24.09.02 |
Detection & IOCsextracted from sources · hover to see the quote
- →Target unauthenticated attack surface: CVE-2025-54466 is exploitable without authentication against the Apache OFBiz scrum plugin — monitor for unexpected code execution or suspicious requests to scrum plugin endpoints from unauthenticated sessions. ↗
- →Patch commit 5a35b4f84f in Apache OFBiz can be used as a reference to identify the vulnerable code path and craft detection logic around the affected scrum plugin functionality. ↗
- ·Vulnerability only applies when the scrum plugin is actively in use — installations without the scrum plugin are not affected. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_apache9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7vg9-49f9-pfxr: Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin
ghsa_unreviewed·2025-08-15
CVE-2025-54466 [MEDIUM] CWE-94 GHSA-7vg9-49f9-pfxr: Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin
Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin.
This issue affects Apache OFBiz: before 24.09.02 only when the scrum plugin is used.
Even unauthenticated attackers can exploit this vulnerability.
Users are recommended to upgrade to version 24.09.02, which fixes the issue.
Apache
Apache ofbiz: CVE-2025-54466
vendor_apache·CVSS 9.8
CVE-2025-54466 [CRITICAL] Apache ofbiz: CVE-2025-54466
Apache ofbiz: CVE-2025-54466
; affected releases before 24.09.02; fixed in 24.09.02 with commit 5a35b4f84f
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-15
Published