CVE-2024-32113
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Apache OFBiz Path Traversal Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 99% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-22
מוצרים מושפעים
apache: ofbiz
קישורים
- https://issues.apache.org/jira/browse/OFBIZ-13006 Vendor Advisory
- https://issues.apache.org/jira/browse/OFBIZ-13006 Vendor Advisory
- https://ofbiz.apache.org/security.html Patch
- https://ofbiz.apache.org/security.html Patch
- http://www.openwall.com/lists/oss-security/2024/05/09/1 Mailing List
- https://lists.apache.org/thread/w6s60okgkxp2th1sr8vx0ndmgk68fqrd Mailing List
- https://ofbiz.apache.org/download.html Product
- http://www.openwall.com/lists/oss-security/2024/05/09/1 Mailing List
- https://lists.apache.org/thread/w6s60okgkxp2th1sr8vx0ndmgk68fqrd Mailing List
- https://ofbiz.apache.org/download.html Product