Apache OFBiz vulnerable to Path Traversal attack
CVE-2024-36104
9.1CRITICAL
Key Information:
- Vendor
- Apache
- Status
- Vendor
- CVE Published:
- 4 June 2024
Badges
๐พ Exploit Exists๐ฐ News Worthy
Summary
Apache OFBiz is affected by a Path Traversal vulnerability that allows attackers to gain unauthorized access to restricted directories. This issue can lead to sensitive data exposure and requires urgent remediation. Users are strongly encouraged to upgrade to version 18.12.14 or later to mitigate this vulnerability effectively.
Affected Version(s)
Apache OFBiz 0 < 18.12.14
Get notified when SecurityVulnerability.io launches alerting ๐
Well keep you posted ๐ง
News Articles
RCE possible with critical Apache OFBiz zero-day
Such a security issue โ which is a patch bypass for the already addressed path traversal flaw, tracked as CVE-2024-36104 โ stems from an authentication mechanism vulnerability enabling unauthenticated access to critical endpoints.
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
- ๐พ
Exploit known to exist
- ๐ฐ
First article discovered by SC Media
Vulnerability published
Vulnerability Reserved
Credit
godspeed (AAA@ZJU)