Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100Vexday Risk Score
Corrige ahora. Ella está bajo explotación confirmada por CISA y tiene exploit funcional público.
ssvc Actcvss 8.1epss 99%
de la publicación al arma0 días
Publicada en NVD5 ago
1ª PoC10 abr
metasploit30 may
CISA KEV+22d
probabilidad de explotación
99%top 1% de las CVE
explotación observada
síCISA + VulnCheck
21 exploit(s) público(s)
Acción exigida por CISAplazo federal: 2024-09-17
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Investigado y redactado con IA a partir del advisory del fabricante y análisis públicos, con las fuentes citadas. Verifica siempre la versión corregida en el advisory oficial antes de actuar.
Incorrect Authorization vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: through 18.12.14.
Users are recommended to upgrade to version 18.12.15, which fixes the issue.
Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check user's permissions because they rely on the configuration of their endpoints).
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Productos afectados
Apache Software Foundation · Apache OFBizPoCs públicas encontradas — 21
githubgithub.com/securelayer7/CVE-2024-38856_Scanner★ 49githubgithub.com/0x20c/CVE-2024-38856-EXP★ 9githubgithub.com/BBD-YZZ/CVE-2024-38856-RCE★ 3githubgithub.com/Hex00-0x4/CVE-2024-38856-Apache-OFBiz★ 3githubgithub.com/Ap0dexMe0/CVE-2024-38856★ 2githubgithub.com/Praison001/CVE-2024-38856-ApacheOfBiz★ 1githubgithub.com/AlissonFaoli/Apache-OFBiz-Exploit★ 1githubgithub.com/emanueldosreis/CVE-2024-38856★ 1vulncheckvulncheck.com/xdb/e14070e9ff4ano verificadovulncheckvulncheck.com/xdb/a05e462ad7f8no verificadovulncheckvulncheck.com/xdb/1c1099b3c2ccno verificadovulncheckvulncheck.com/xdb/b695c336103dno verificadovulncheckvulncheck.com/xdb/c3ab768a1b72no verificadovulncheckvulncheck.com/xdb/9489a533c3abno verificadovulncheckvulncheck.com/xdb/034aa8828710no verificadovulncheckvulncheck.com/xdb/edb9d392f8e8no verificadovulncheckvulncheck.com/xdb/cd8eee41112dno verificadovulncheckvulncheck.com/xdb/22ff4506fd33no verificadovulncheckvulncheck.com/xdb/f6c5ff007112no verificadovulncheckvulncheck.com/xdb/d832bf48d567no verificadovulncheckvulncheck.com/xdb/2ca2a8c3b393no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
https://issues.apache.org/jira/browse/OFBIZ-13128https://lists.apache.org/thread/olxxjk6b13sl3wh9cmp0k2dscvp24l7whttps://ofbiz.apache.org/download.htmlhttps://ofbiz.apache.org/security.htmlhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-38856http://www.openwall.com/lists/oss-security/2024/08/04/1