ZeroHour

CVE-2024-25065

CVSS 3.1
9.1 critical
EPSS
48%p99
Published
()
Modified
Description

Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.

Vendors
apache
Products
ofbiz
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.