CVE-2024-25065: Apache OFBiz: Path traversal allowing authentication bypass.
Published Feb 28, 2024
·Updated
Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.
Affected Software
2 affected components
Apache OFBiz<18.12.12
Apache OFBiz<18.12.12
Event History
Feb 28, 2024
CVE Published
via MITRE·03:42 PM
Data Sourced
via MITRE·03:42 PM
DescriptionWeakness
Feb 29, 2024
Data Sourced
via NVD·01:44 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-25065?
CVE-2024-25065 has a high severity rating due to its ability to allow authentication bypass through path traversal.
2
How do I fix CVE-2024-25065?
To fix CVE-2024-25065, upgrade Apache OFBiz to version 18.12.12 or later.
3
Which versions of Apache OFBiz are affected by CVE-2024-25065?
CVE-2024-25065 affects all versions of Apache OFBiz prior to 18.12.12.
4
What is the impact of CVE-2024-25065 on Apache OFBiz users?
The impact of CVE-2024-25065 includes the potential for unauthorized access to the system due to authentication bypass.
5
Is there a workaround for CVE-2024-25065 until I can upgrade?
There are no known workarounds for CVE-2024-25065, so immediate upgrading is recommended.