Record summary

CVE-2023-50968 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations. The same uri can be operated to realize a SSRF attack also without authorizations. Users are recommended to upgrade to version 18.12.11, which fixes this issue.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 21, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Default status: unaffected

CVE ListThrough 18.12.10affected

Nuclei templates

1
ProjectDiscoveryHIGHApache OFBiz < 18.12.11 - Server Side Request ForgeryCVSS 7.5

Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations. The same uri can be operated to realize a SSRF attack also without authorizations. Users are recommended to upgrade to version 18.12.11, which fixes this issue.

Impact

Unauthenticated attackers can read arbitrary file properties and perform SSRF attacks, potentially accessing sensitive internal resources or configuration files.

Remediation

Upgrade Apache OFBiz to version 18.12.11 or later.

WeaknessesCWE-918CWE-200
Authorsyour3cho
Template tagscvecve2023apacheofbizssrfvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:*
Shodan: html:"OFBiz"
Shodan: http.html:"ofbiz"
Shodan: ofbiz.visitor=
FOFA: app="Apache_OFBiz"
FOFA: body="ofbiz"
FOFA: app="apache_ofbiz"

Source: ProjectDiscovery

References

7