Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 18.12.17.
Users are recommended to upgrade to version 18.12.17, which fixes the issue.
Metrics
Affected Vendors & Products
References
History
Tue, 24 Jun 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apache
Apache ofbiz |
|
CPEs | cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:* | |
Vendors & Products |
Apache
Apache ofbiz |
Fri, 22 Nov 2024 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Tue, 19 Nov 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Mon, 18 Nov 2024 09:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.17. Users are recommended to upgrade to version 18.12.17, which fixes the issue. | |
Title | Apache OFBiz: URLs allowing remote use of Groovy expressions, leading to RCE | |
Weaknesses | CWE-918 CWE-94 |
|
References |
|

Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-11-19T14:59:02.765Z
Reserved: 2024-09-21T11:29:47.639Z
Link: CVE-2024-47208

Updated: 2024-11-18T09:03:46.416Z

Status : Analyzed
Published: 2024-11-18T09:15:06.100
Modified: 2025-06-24T16:20:57.757
Link: CVE-2024-47208

No data.