Executive brief
Apache OFBiz contains a path traversal vulnerability (CWE-22) that allows for remote code execution. The flaw exists due to improper limitation of a pathname to a restricted directory, affecting versions prior to 18.12.13.
Affected products
- Apache OFBiz before 18.12.13
Timeline
- 2024-05-08: disclosed: CVE received from Apache Software Foundation
- 2024-05-09: other: Public announcement on oss-security mailing list
- 2024-08-07: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-08-07: advisory: NVD publication date