Executive brief
Apache OFBiz contains an incorrect authorization vulnerability where unauthenticated endpoints may allow the execution of screen rendering code. This can be leveraged by a remote attacker to achieve code execution via a Groovy payload in the context of the OFBiz user process.
Affected products
- Apache OFBiz through 18.12.14
Timeline
- 2024-08-05: disclosed: Vulnerability reported by Apache Software Foundation
- 2024-08-27: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-08-27: advisory: NVD publication date
- 2024-08-27: exploited: Confirmed exploited in the wild per CISA KEV entry
- 2024-08-05: patched: Version 18.12.15 released to address the issue