Record summary

CVE-2021-29200 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListApache OFBiz to < 17.12.07affected

Nuclei templates

1
ProjectDiscoveryCRITICALApache OFBiz < 17.12.07 - Arbitrary Code ExecutionCVSS 9.8

Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack

Impact

Unauthenticated attackers can exploit unsafe deserialization to execute arbitrary code, leading to complete server compromise.

Remediation

Upgrade to Apache OFBiz version 17.12.07 or later.

WeaknessesCWE-502
Authorsyour3cho
Template tagscve2021cveapacheofbizdeserializationrcevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:*
Shodan: html:"OFBiz"
Shodan: http.html:"ofbiz"
Shodan: ofbiz.visitor=
FOFA: app="Apache_OFBiz"
FOFA: body="ofbiz"
FOFA: app="apache_ofbiz"

Source: ProjectDiscovery

References

Showing 12 of 14