CRITICAL

CVE-2024-32113

Apache Ofbiz 2024-05-08 CVSS v3.1
CVSS
9.8
KEV

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13.

Users are recommended to upgrade to version 18.12.13, which fixes the issue.

Summary dbcve.org

A path traversal vulnerability in Apache OFBiz allows attackers to manipulate file paths using '..' sequences to access files outside the intended web root directory, potentially exposing sensitive system files. This occurs due to improper validation of user-supplied file paths before use in file operations.

Mitigation

Upgrade Apache OFBiz to version 18.12.13 or later to patch this critical path traversal vulnerability.

Patch Commit

Weakness (CWE)

CWE-22 Path Traversal

EPSS Score

99.44%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE