CVE-2021-26295
CRITICAL EXPLOITED NUCLEIApache OFBiz SOAP Java Deserialization
Title source: metasploitExploitation Summary
CVE-2021-26295 has been observed exploited in the wild (reported by VulnCheck KEV).
EIP tracks 6 public exploits from researchers including yumusb, yuaneuro, rakjong, including a Metasploit module exploits/linux/http/apache_ofbiz_deserialization_soap.
A Nuclei detection template is also available.
AI-analyzed exploit summary This repository contains functional exploit code for CVE-2021-26295, a deserialization vulnerability in Apache OFBiz. The PoC uses ysoserial to generate payloads and includes both a detection script (poc.py) and an exploitation script (exp.py) for command execution.
Description
Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.
Exploits (6)
This repository contains functional exploit code for CVE-2021-26295, a deserialization vulnerability in Apache OFBiz. The PoC uses ysoserial to generate payloads and includes both a detection script (poc.py) and an exploitation script (exp.py) for command execution.
This repository contains functional exploit code for CVE-2021-26295, a deserialization vulnerability in Apache OFBiz. The PoC leverages ysoserial to generate malicious payloads and uses DNS logging for verification, demonstrating remote code execution capabilities.
This PoC exploits CVE-2021-26295, a deserialization vulnerability in Apache OFBiz, by sending a crafted SOAP request containing a serialized payload generated via ysoserial.jar. The payload triggers a DNS lookup to a specified dnslog, confirming successful exploitation.
The repository claims to provide a PoC for CVE-2021-26295 but lacks actual exploit code, instead directing users to external resources or vague instructions. The README is minimal and does not include technical details about the vulnerability.
This repository contains a functional exploit for CVE-2021-26295, an Apache OFBiz deserialization vulnerability. The exploit uses ysoserial to generate a malicious payload and sends it via a SOAP request to achieve remote code execution.
This Metasploit module exploits a Java deserialization vulnerability in Apache OFBiz's unauthenticated SOAP endpoint for versions prior to 17.12.06. It leverages the ROME library to execute arbitrary commands via a crafted serialized object.
Nuclei Templates (1)
OFBiz.Visitor= || http.html:"ofbiz" || ofbiz.visitor=
body="ofbiz" || app="apache_ofbiz"
References (13)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H