CRITICAL
CVE-2024-32113
CVSS
9.8
KEV
Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13.
Users are recommended to upgrade to version 18.12.13, which fixes the issue.
Summary dbcve.org
A path traversal vulnerability in Apache OFBiz allows attackers to manipulate file paths using '..' sequences to access files outside the intended web root directory, potentially exposing sensitive system files. This occurs due to improper validation of user-supplied file paths before use in file operations.
Mitigation
Upgrade Apache OFBiz to version 18.12.13 or later to patch this critical path traversal vulnerability.
Weakness (CWE)
CWE-22
Path Traversal
EPSS Score
99.44%
Probability of exploitation in next 30 days
99.9th percentile
References
http://www.openwall.com/lists/oss-security/2024/05/09/1
Mailing List
https://issues.apache.org/jira/browse/OFBIZ-13006
Vendor Advisory
https://lists.apache.org/thread/w6s60okgkxp2th1sr8vx0ndmgk68fqrd
Mailing List
https://ofbiz.apache.org/download.html
Product
https://ofbiz.apache.org/security.html
Patch
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-32113
Third Party Advisory, US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.