First published: Mon Aug 23 2021(Updated: )
In Apache Ofbiz, versions v17.12.01 to v17.12.07 implement a try catch exception to handle errors at multiple locations but leaks out sensitive table info which may aid the attacker for further recon. A user can register with a very long password, but when he tries to login with it an exception occurs.
Credit: vulnerabilitylab@mend.io
Affected Software | Affected Version | How to fix |
---|---|---|
Apache OFBiz | >=17.12.01<17.12.08 |
Update to version release17.12.08
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25958 is a vulnerability in Apache Ofbiz versions v17.12.01 to v17.12.07 that leaks out sensitive table info, potentially aiding attackers in further recon.
CVE-2021-25958 allows a user to register with a very long password, and when attempting to login with it, an exception occurs that exposes sensitive table information.
CVE-2021-25958 has a severity rating of high, with a CVSS score of 7.5.
To mitigate CVE-2021-25958, update your Apache Ofbiz version to 17.12.08 or later.
You can find more information about CVE-2021-25958 in the Apache Ofbiz GitHub repository and the WhiteSource Software vulnerability database.