CVE-2024-45507: Apache OFBiz: Prevent use of URLs in files when loading them from Java or Groovy, leading to a RCE
Published Sep 3, 2024
·Updated
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 18.12.16.
Users are recommended to upgrade to version 18.12.16, which fixes the issue.
Affected Software
1 affected component
Apache OFBiz<18.12.16
Remediation
Patch Available
Patch Available
Event History
Sep 4, 2024
CVE Published
via MITRE·08:08 AM
Data Sourced
via MITRE·08:08 AM
DescriptionWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-45507?
CVE-2024-45507 has a high severity level due to the potential for Server-Side Request Forgery (SSRF) attacks.
2
How do I fix CVE-2024-45507?
To fix CVE-2024-45507, users should upgrade Apache OFBiz to version 18.12.16 or later.
3
What type of vulnerability is CVE-2024-45507?
CVE-2024-45507 is categorized as a Server-Side Request Forgery (SSRF) vulnerability.
4
Which versions of Apache OFBiz are affected by CVE-2024-45507?
CVE-2024-45507 affects Apache OFBiz versions prior to 18.12.16.
5
What are the potential risks associated with CVE-2024-45507?
The potential risks of CVE-2024-45507 include unauthorized access to internal resources and exploitation of sensitive data.