CVE-2024-45507
Apache OFBiz: Prevent use of URLs in files when loading them from Java or Groovy, leading to a RCE
Record summary
CVE-2024-45507 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.
Exploitation context
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| VulnCheck | Version data not supplied | ||
Apache OFBizBrowse Apache Software Foundation / Apache OFBizDefault status: unaffected, unknown | CVE List | Before 18.12.16 | affected |
Proofs of concept
1Repository PoCs
GitHubAvento/CVE-2024-45507_Behinder_WebshellRepository PoCby AventoStars: 0Not analyzed1 file
Nuclei templates
1ProjectDiscoveryCRITICALApache OFBiz - Remote Code ExecutionCVSS 9.8
Apache OFBiz below 18.12.16 is vulnerable to unauthenticated remote code execution on Linux and Windows. An attacker with no valid credentials can exploit missing view authorization checks in the web application to execute arbitrary code on the server
Impact
Unauthenticated attackers can exploit missing view authorization checks to execute arbitrary code on Apache OFBiz servers.
Remediation
Users are recommended to upgrade to version 18.12.16, which fixes the issue.
Source: ProjectDiscovery