[oss-security] 20210427 [CVE-2021-29200] RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMImailing list
http://www.openwall.com/lists/oss-security/2021/04/27/4 CVE-2021-29200
CRITICALNuclei
RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI
Record summary
CVE-2021-29200 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Apache OFBizBrowse Apache Software Foundation / Apache OFBiz | CVE List | Apache OFBiz to < 17.12.07 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALApache OFBiz < 17.12.07 - Arbitrary Code ExecutionCVSS 9.8
Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack
Impact
Unauthenticated attackers can exploit unsafe deserialization to execute arbitrary code, leading to complete server compromise.
Remediation
Upgrade to Apache OFBiz version 17.12.07 or later.
WeaknessesCWE-502
Authorsyour3cho
Template tagscve2021cveapacheofbizdeserializationrcevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:*
Shodan: html:"OFBiz"
Shodan: http.html:"ofbiz"
Shodan: ofbiz.visitor=
FOFA: app="Apache_OFBiz"
FOFA: body="ofbiz"
FOFA: app="apache_ofbiz"
http://www.openwall.com/lists/oss-security/2021/04/27/4 https://nvd.nist.gov/vuln/detail/CVE-2021-29200 https://github.com/freeide/CVE-2021-29200 https://lists.apache.org/thread.html/r108a964764b8bd21ebd32ccd4f51c183ee80a251c105b849154a8e9d%40%3Ccommits.ofbiz.apache.org%3E https://lists.apache.org/thread.html/r708351f1a8af7adb887cc3d8a92bed8fcbff4a9e495e69a9ee546fda%40%3Cnotifications.ofbiz.apache.org%3E
Source: ProjectDiscovery
References
Showing 12 of 14[ofbiz-commits] 20210427 [ofbiz-site] branch master updated: Updates security page for CVE-2021-29200 and 30128 fixed in 17.12.07mailing list
https://lists.apache.org/thread.html/r108a964764b8bd21ebd32ccd4f51c183ee80a251c105b849154a8e9d%40%3Ccommits.ofbiz.apache.org%3E lists.apache.org
https://lists.apache.org/thread.html/r108a964764b8bd21ebd32ccd4f51c183ee80a251c105b849154a8e9d@%3Ccommits.ofbiz.apache.org%3E [ofbiz-notifications] 20210427 [jira] [Updated] (OFBIZ-12216) Fixed UtilObject class [CVE-2021-29200]mailing list
https://lists.apache.org/thread.html/r708351f1a8af7adb887cc3d8a92bed8fcbff4a9e495e69a9ee546fda%40%3Cnotifications.ofbiz.apache.org%3E lists.apache.org
https://lists.apache.org/thread.html/r708351f1a8af7adb887cc3d8a92bed8fcbff4a9e495e69a9ee546fda@%3Cnotifications.ofbiz.apache.org%3E [ofbiz-commits] 20210811 [ofbiz-site] branch master updated: Updates security page for CVE-2021-37608 fixed in 17.12.08mailing list
https://lists.apache.org/thread.html/rbe8439b26a71fc3b429aa793c65dcc4a6e349bc7bb5010746a74fa1d%40%3Ccommits.ofbiz.apache.org%3E lists.apache.org
https://lists.apache.org/thread.html/rbe8439b26a71fc3b429aa793c65dcc4a6e349bc7bb5010746a74fa1d@%3Ccommits.ofbiz.apache.org%3E [announce] 20210427 [CVE-2021-29200] RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMImailing list
https://lists.apache.org/thread.html/re21d25d9fb89e36cea910633779c23f144b9b60596b113b7bf1e8097%40%3Cannounce.apache.org%3E lists.apache.org
https://lists.apache.org/thread.html/re21d25d9fb89e36cea910633779c23f144b9b60596b113b7bf1e8097%40%3Cdev.ofbiz.apache.org%3E [ofbiz-user] 20210427 [CVE-2021-29200] RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMImailing list
https://lists.apache.org/thread.html/re21d25d9fb89e36cea910633779c23f144b9b60596b113b7bf1e8097%40%3Cuser.ofbiz.apache.org%3E lists.apache.org
https://lists.apache.org/thread.html/re21d25d9fb89e36cea910633779c23f144b9b60596b113b7bf1e8097@%3Cannounce.apache.org%3E lists.apache.org
https://lists.apache.org/thread.html/re21d25d9fb89e36cea910633779c23f144b9b60596b113b7bf1e8097@%3Cdev.ofbiz.apache.org%3E