CVE-2024-38856
critical · 9.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check user's permissions because they rely on the configuration of their endpoints).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | ofbiz | < 18.12.15 |
Check a specific version with /api/v1/cve/match.
References
- https://issues.apache.org/jira/browse/OFBIZ-13128
- https://lists.apache.org/thread/olxxjk6b13sl3wh9cmp0k2dscvp24l7w
- https://ofbiz.apache.org/download.html
- https://ofbiz.apache.org/security.html
- http://www.openwall.com/lists/oss-security/2024/08/04/1
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-38856
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2024-38856