CVE-2024-38856

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/08/2024
Last modified:
20/12/2024

Description

Incorrect Authorization vulnerability in Apache OFBiz.<br /> <br /> This issue affects Apache OFBiz: through 18.12.14.<br /> <br /> Users are recommended to upgrade to version 18.12.15, which fixes the issue.<br /> <br /> Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don&amp;#39;t explicitly check user&amp;#39;s permissions because they rely on the configuration of their endpoints).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:* 18.12.15 (excluding)