Apache OFBiz: Arbitrary file properties reading and SSRF attack
CVE-2023-50968
Key Information:
- Vendor
Apache
- Status
- Vendor
- CVE Published:
- 26 December 2023
Badges
What is CVE-2023-50968?
An arbitrary file properties reading vulnerability exists in Apache OFBiz that allows unauthorized users to execute URI calls without proper access controls. This vulnerability also opens the door to a possible Server-Side Request Forgery (SSRF) attack, enabling unauthenticated users to manipulate requests to internal systems. It is critical for users of affected versions to upgrade to version 18.12.11 to mitigate these security risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache OFBiz 0 <= 18.12.10
News Articles
References
EPSS Score
82% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- ๐ฐ
First article discovered by Security Boulevard
Vulnerability published
Vulnerability Reserved