First published: Thu Apr 30 2020(Updated: )
Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache OFBiz | =17.12.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for Apache OFBiz 17.12.01 is CVE-2019-12425.
CVE-2019-12425 has a severity of high.
The affected software version of CVE-2019-12425 is Apache OFBiz 17.12.01.
CVE-2019-12425 allows for Host header injection by accepting arbitrary host, which can lead to various attacks, including request smuggling or cross-site scripting.
To fix CVE-2019-12425, it is recommended to update Apache OFBiz to a patched version or apply the necessary security patches provided by the vendor.