CVE-2023-50968
Apache OFBiz: Arbitrary file properties reading and SSRF attack
Record summary
CVE-2023-50968 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations. The same uri can be operated to realize a SSRF attack also without authorizations. Users are recommended to upgrade to version 18.12.11, which fixes this issue.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 21, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| VulnCheck | Version data not supplied | ||
Apache OFBizBrowse Apache Software Foundation / Apache OFBizDefault status: unaffected | CVE List | Through 18.12.10 | affected |
Nuclei templates
1ProjectDiscoveryHIGHApache OFBiz < 18.12.11 - Server Side Request ForgeryCVSS 7.5
Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations. The same uri can be operated to realize a SSRF attack also without authorizations. Users are recommended to upgrade to version 18.12.11, which fixes this issue.
Impact
Unauthenticated attackers can read arbitrary file properties and perform SSRF attacks, potentially accessing sensitive internal resources or configuration files.
Remediation
Upgrade Apache OFBiz to version 18.12.11 or later.
Source: ProjectDiscovery