CVE-2021-26295

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
22/03/2021
Last modified:
07/11/2023

Description

Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:* 17.12.06 (excluding)


References to Advisories, Solutions, and Tools