CVE-2019-12425: CSRF
Published Apr 30, 2020
·Updated
Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host
Affected Software
1 affected component
Apache OFBiz=17.12.01
Remediation
Event History
Apr 30, 2020
CVE Published
via MITRE·07:20 PM
Data Sourced
via MITRE·07:20 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for Apache OFBiz 17.12.01?
The vulnerability ID for Apache OFBiz 17.12.01 is CVE-2019-12425.
2
What is the severity of CVE-2019-12425?
CVE-2019-12425 has a severity of high.
3
What is the affected software version of CVE-2019-12425?
The affected software version of CVE-2019-12425 is Apache OFBiz 17.12.01.
4
What is the impact of CVE-2019-12425?
CVE-2019-12425 allows for Host header injection by accepting arbitrary host, which can lead to various attacks, including request smuggling or cross-site scripting.
5
How can CVE-2019-12425 be fixed?
To fix CVE-2019-12425, it is recommended to update Apache OFBiz to a patched version or apply the necessary security patches provided by the vendor.