CVE-2024-32113: Apache OFBiz Path Traversal Vulnerability
Apache OFBiz contains a path traversal vulnerability that could allow for remote code execution.
Other sources
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13.
Users are recommended to upgrade to version 18.12.13, which fixes the issue.
— NVD
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache OFBizto a version that resolves this vulnerability.Fixed in 18.12.13 - Remove
Remove
Apache OFBizfrom your environment.Discontinue use of the product if mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32113?
CVE-2024-32113 is considered to have a high severity due to the potential for remote code execution.
How do I fix CVE-2024-32113?
To fix CVE-2024-32113, upgrade to Apache OFBiz version 18.12.13 or later.
What does CVE-2024-32113 affect?
CVE-2024-32113 affects Apache OFBiz versions prior to 18.12.13.
What type of vulnerability is CVE-2024-32113?
CVE-2024-32113 is a path traversal vulnerability that could lead to remote code execution.
Is there a workaround for CVE-2024-32113 before upgrading?
No specific workarounds are recommended for CVE-2024-32113; upgrading is the best mitigation.