CVE-2023-50968

Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations. The same uri can be operated to realize a SSRF attack also without authorizations. Users are recommended to upgrade to version 18.12.11, which fixes this issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:*

History

04 Jan 2024, 03:01

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2023/12/26/2 - () http://www.openwall.com/lists/oss-security/2023/12/26/2 - Mailing List, Third Party Advisory
References () https://issues.apache.org/jira/browse/OFBIZ-12875 - () https://issues.apache.org/jira/browse/OFBIZ-12875 - Issue Tracking, Patch, Vendor Advisory
References () https://lists.apache.org/thread/x5now4bk3llwf3k58kl96qvtjyxwp43q - () https://lists.apache.org/thread/x5now4bk3llwf3k58kl96qvtjyxwp43q - Mailing List, Vendor Advisory
References () https://ofbiz.apache.org/download.html - () https://ofbiz.apache.org/download.html - Product
References () https://ofbiz.apache.org/release-notes-18.12.11.html - () https://ofbiz.apache.org/release-notes-18.12.11.html - Release Notes
References () https://ofbiz.apache.org/security.html - () https://ofbiz.apache.org/security.html - Vendor Advisory
First Time Apache
Apache ofbiz
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:*

26 Dec 2023, 20:34

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de lectura de propiedades de archivos arbitrarias en Apache Software Foundation Apache OFBiz cuando el usuario realiza una llamada uri sin autorización. El mismo uri puede utilizarse para realizar un ataque SSRF también sin autorización. Se recomienda a los usuarios actualizar a la versión 18.12.11, que soluciona este problema.

26 Dec 2023, 15:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2023/12/26/2 -

26 Dec 2023, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-26 12:15

Updated : 2024-01-04 03:01


NVD link : CVE-2023-50968

Mitre link : CVE-2023-50968

CVE.ORG link : CVE-2023-50968


JSON object : View

Products Affected

apache

  • ofbiz
CWE
CWE-918

Server-Side Request Forgery (SSRF)

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor