CVE-2023-50968
Severity CVSS v4.0:
Pending analysis
Type:
CWE-918
Server-Side Request Forgery (SSRF)
Publication date:
26/12/2023
Last modified:
04/01/2024
Description
Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations.<br />
<br />
The same uri can be operated to realize a SSRF attack also without authorizations.<br />
<br />
Users are recommended to upgrade to version 18.12.11, which fixes this issue.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:* | 18.12.11 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.openwall.com/lists/oss-security/2023/12/26/2
- https://issues.apache.org/jira/browse/OFBIZ-12875
- https://lists.apache.org/thread/x5now4bk3llwf3k58kl96qvtjyxwp43q
- https://ofbiz.apache.org/download.html
- https://ofbiz.apache.org/release-notes-18.12.11.html
- https://ofbiz.apache.org/security.html