Lucene search

K
cve[email protected]CVE-2023-50968
HistoryDec 26, 2023 - 12:15 p.m.

CVE-2023-50968

2023-12-2612:15:07
CWE-918
CWE-200
web.nvd.nist.gov
31
cve-2023-50968
apache
apache ofbiz
ssrf
vulnerability
file properties
nvd
security fix

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.29 Low

EPSS

Percentile

96.9%

Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations.

The same uri can be operated to realize a SSRF attack also without authorizations.

Users are recommended to upgrade to version 18.12.11, which fixes this issue.

Affected configurations

Vulners
NVD
Node
apacheofbizRange18.12.10
CPENameOperatorVersion
apache:ofbizapache ofbizlt18.12.11

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Apache OFBiz",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThanOrEqual": "18.12.10",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.29 Low

EPSS

Percentile

96.9%

Related for CVE-2023-50968