Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-50968
HistoryDec 26, 2023 - 12:15 p.m.

Design/Logic Flaw

2023-12-2612:15:00
PRIOn knowledge base
www.prio-n.com
4
apache
ofbiz
ssrf
vulnerability
upgrade
nvd

7 High

AI Score

Confidence

Low

0.29 Low

EPSS

Percentile

96.9%

Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations.

The same uri can be operated to realize a SSRF attack also without authorizations.

Users are recommended to upgrade to version 18.12.11, which fixes this issue.

CPENameOperatorVersion
ofbizlt18.12.11

7 High

AI Score

Confidence

Low

0.29 Low

EPSS

Percentile

96.9%

Related for PRION:CVE-2023-50968