CVE-2024-47208
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Nov 18, 2024
Updated: Nov 21, 2024
CWE ID 94
CWE ID 918
Summary
CVE-2024-47208 is a serious vulnerability affecting Apache OFBiz versions before 18.12.17. The issue involves both a Server-Side Request Forgery (SSRF) and an Improper Control of Generation of Code ('Code Injection') vulnerability. An attacker could exploit this flaw to execute arbitrary commands and potentially gain unauthorized access to resources. To mitigate this risk, it is strongly recommended that users upgrade to the latest version, Apache OFBiz 18.12.17, which includes the necessary patches to resolve the vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Apache OFBiz
Affected Vendors
- Apache Software Foundation