CVE-2023-51467: Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability
Published Dec 26, 2023
·Updated
The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code
Affected Software
2 affected components
Apache OFBiz<18.12.11
Apache OFBiz=18.12.11
Remediation
Patch Available
Event History
Dec 26, 2023
CVE Published
via MITRE·02:46 PM
Data Sourced
via MITRE·02:46 PM
DescriptionWeakness
Dec 28, 2023
News Published
04:20 PM
Jan 8, 2024
News Published
via The Register·05:45 PM
Jan 20, 2024
News Published
via The Register·05:49 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-51467?
CVE-2023-51467 is rated as critical due to its ability to allow attackers to bypass authentication and execute arbitrary code remotely.
2
How do I fix CVE-2023-51467?
To fix CVE-2023-51467, upgrade Apache OFBiz to version 18.12.11 or a later version.
3
Which versions of Apache OFBiz are affected by CVE-2023-51467?
CVE-2023-51467 affects Apache OFBiz versions prior to 18.12.11, specifically 18.12.10 and earlier.
4
Can CVE-2023-51467 be exploited remotely?
Yes, CVE-2023-51467 allows attackers to exploit the vulnerability remotely if they can access the application.
5
What type of vulnerability is CVE-2023-51467?
CVE-2023-51467 is an authentication bypass vulnerability that enables arbitrary code execution.