CVE-2023-50968 Information

Description

Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations.

The same uri can be operated to realize a SSRF attack also without authorizations.

Users are recommended to upgrade to version 18.12.11 which fixes this issue.

Reference

https://ofbiz.apache.org/download.html https://ofbiz.apache.org/security.html https://ofbiz.apache.org/release-notes-18.12.11.html https://issues.apache.org/jira/browse/OFBIZ-12875 https://lists.apache.org/thread/x5now4bk3llwf3k58kl96qvtjyxwp43q http://www.openwall.com/lists/oss-security/2023/12/26/2

Share on: