Junglewise Threat Intelligence

CVE-2024-38856: Apache OFBiz Incorrect Authorization Vulnerability

CVE-2024-38856 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-08-27

Technologies: Apache OFBiz. Vendors: Apache.

Executive brief

Apache OFBiz contains an incorrect authorization vulnerability where unauthenticated endpoints may allow the execution of screen rendering code. This can be leveraged by a remote attacker to achieve code execution via a Groovy payload in the context of the OFBiz user process.

Affected products

  • Apache OFBiz through 18.12.14

Timeline

  • 2024-08-05: disclosed: Vulnerability reported by Apache Software Foundation
  • 2024-08-27: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-08-27: advisory: NVD publication date
  • 2024-08-27: exploited: Confirmed exploited in the wild per CISA KEV entry
  • 2024-08-05: patched: Version 18.12.15 released to address the issue

Related threats