Record summary

CVE-2024-45507 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 5, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 12, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Default status: unaffected, unknown

CVE ListBefore 18.12.16affected

Proofs of concept

1

Repository PoCs

GitHubAvento/CVE-2024-45507_Behinder_WebshellRepository PoCby AventoStars: 0Not analyzed1 file

13.4 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALApache OFBiz - Remote Code ExecutionCVSS 9.8

Apache OFBiz below 18.12.16 is vulnerable to unauthenticated remote code execution on Linux and Windows. An attacker with no valid credentials can exploit missing view authorization checks in the web application to execute arbitrary code on the server

Impact

Unauthenticated attackers can exploit missing view authorization checks to execute arbitrary code on Apache OFBiz servers.

Remediation

Users are recommended to upgrade to version 18.12.16, which fixes the issue.

WeaknessesCWE-918
Authorschybeta, iamnooob, rootxharsh, pdresearch
Template tagscvecve2024apacheobizrceoastvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:*
Shodan: ofbiz.visitor=
Shodan: http.html:"ofbiz"
FOFA: app="apache_ofbiz"
FOFA: body="ofbiz"

Source: ProjectDiscovery

References

6