Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 18.12.17.
Users are recommended to upgrade to version 18.12.17, which fixes the issue.
Metrics
Affected Vendors & Products
References
History
Tue, 24 Jun 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache ofbiz |
|
| CPEs | cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache
Apache ofbiz |
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 19 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 18 Nov 2024 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.17. Users are recommended to upgrade to version 18.12.17, which fixes the issue. | |
| Title | Apache OFBiz: URLs allowing remote use of Groovy expressions, leading to RCE | |
| Weaknesses | CWE-918 CWE-94 |
|
| References |
|
Status: PUBLISHED
Assigner: apache
Published: 2024-11-18T08:43:17.743Z
Updated: 2024-11-19T14:59:02.765Z
Reserved: 2024-09-21T11:29:47.639Z
Link: CVE-2024-47208
Updated: 2024-11-18T09:03:46.416Z
Status : Analyzed
Published: 2024-11-18T09:15:06.100
Modified: 2025-06-24T16:20:57.757
Link: CVE-2024-47208
No data.