CVE-2024-47208

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Nov 18, 2024
Updated: Nov 21, 2024
CWE ID 94
CWE ID 918

Summary

CVE-2024-47208 is a serious vulnerability affecting Apache OFBiz versions before 18.12.17. The issue involves both a Server-Side Request Forgery (SSRF) and an Improper Control of Generation of Code ('Code Injection') vulnerability. An attacker could exploit this flaw to execute arbitrary commands and potentially gain unauthorized access to resources. To mitigate this risk, it is strongly recommended that users upgrade to the latest version, Apache OFBiz 18.12.17, which includes the necessary patches to resolve the vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Apache OFBiz

Affected Vendors

  • Apache Software Foundation