Apache fixes critical OFBiz remote code execution vulnerability
ID: b508bddf-00a1-5bb9-aa3b-0a312562edbf
STIX ID: report--b508bddf-00a1-5bb9-aa3b-0a312562edbf
Feed Name: Bleeping Computer
Threat Score
Apache fixed a critical unauthenticated remote code execution vulnerability in OFBiz (CVE-2024-45195) that allows attackers to bypass view authorization and execute arbitrary code; Rapid7 published a report with PoC and the issue patches previous CVEs with the same root cause. Users are urged to upgrade to OFBiz 18.12.16 immediately, as related OFBiz flaws have been actively exploited and have been added to CISA's known-exploited vulnerabilities catalog.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
