CVE-2021-25958: Generation of Error Message Containing Sensitive Information in Apache OFBiz
In Apache Ofbiz, versions v17.12.01 to v17.12.07 implement a try catch exception to handle errors at multiple locations but leaks out sensitive table info which may aid the attacker for further recon. A user can register with a very long password, but when he tries to login with it an exception occurs.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-25958?
CVE-2021-25958 is a vulnerability in Apache Ofbiz versions v17.12.01 to v17.12.07 that leaks out sensitive table info, potentially aiding attackers in further recon.
How does CVE-2021-25958 impact Apache Ofbiz?
CVE-2021-25958 allows a user to register with a very long password, and when attempting to login with it, an exception occurs that exposes sensitive table information.
What is the severity of CVE-2021-25958?
CVE-2021-25958 has a severity rating of high, with a CVSS score of 7.5.
How can I mitigate CVE-2021-25958 in Apache Ofbiz?
To mitigate CVE-2021-25958, update your Apache Ofbiz version to 17.12.08 or later.
Where can I find more information about CVE-2021-25958?
You can find more information about CVE-2021-25958 in the Apache Ofbiz GitHub repository and the WhiteSource Software vulnerability database.