cbcvebase.
CVE-2025-54466
published 2025-08-15

CVE-2025-54466: Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Apache…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Apache OFBiz: before 24.09.02 only when the scrum plugin is used. Even unauthenticated attackers can exploit this vulnerability. Users are recommended to upgrade to version 24.09.02, which fixes the issue.

Affected

3 ranges
VendorProductVersion rangeFixed in
apacheofbiz< 24.09.0224.09.02
apacheofbiz
apache_software_foundationapache_ofbiz< 24.09.0224.09.02