First published: Tue Sep 03 2024(Updated: )
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache OFBiz | <18.12.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-45507 has a high severity level due to the potential for Server-Side Request Forgery (SSRF) attacks.
To fix CVE-2024-45507, users should upgrade Apache OFBiz to version 18.12.16 or later.
CVE-2024-45507 is categorized as a Server-Side Request Forgery (SSRF) vulnerability.
CVE-2024-45507 affects Apache OFBiz versions prior to 18.12.16.
The potential risks of CVE-2024-45507 include unauthorized access to internal resources and exploitation of sensitive data.