ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Critical Apache OFBiz pre-auth RCE flaw fixed, update ASAP! (CVE-2024-38856)

criticalVulnerability exploited in the wildimportance 60CVE-2024-38856CVE-2024-36104CVE-2024-32113

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-32113
Critical Unauthenticated Path Traversal in Apache OFBiz

Apache OFBiz before 18.12.13 contains a path traversal vulnerability (CWE-22) in which improper limitation of a pathname allows access to restricted directories outside the intended scope. Per the CVSS vector (AV:N/AC:L/PR:N/UI:N), the flaw can be triggered remotely by an unauthenticated attacker with no user interaction. Successful exploitation has high impact on confidentiality, integrity, and availability: an attacker can reach files and directories that should be restricted, and the critical 9.8 score indicates potential full compromise of the affected server. Any organization running an affected version of the open-source Apache OFBiz ERP/enterprise automation suite is exposed. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-08-07, and EPSS assigns a 99.4% probability of exploitation within 30 days (100th percentile), amid a wave of critical OFBiz flaws patched in 2024.

Do: Upgrade all Apache OFBiz instances to version 18.12.13 or later immediately, per the vendor fix and CISA KEV required action. Because the flaw is under active exploitation, prioritize any OFBiz servers exposed to the internet, hunt for signs of compromise on unpatched systems, and restrict network access to OFBiz until patched.

9.899% KEV
  • Apache OFBiz all versions before 18.12.13 (fixed in 18.12.13)
moderateseveral thousand internet-exposed OFBiz instances (estimate, on the order of 10^3)
CVE-2024-36104
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.14. Users are recommended to upgrade to version 18.12.14, which fixes the issue.

NVD description · AI analysis pending
9.188%
  • apache ofbiz
CVE-2024-38856
Pre-auth RCE via Incorrect Authorization in Apache OFBiz

CVE-2024-38856 is an incorrect authorization flaw (CWE-863) in Apache OFBiz, an open-source ERP and e-commerce platform, affecting all versions through 18.12.14. On deployments where screen definitions do not explicitly verify a user's permissions because they rely on the configuration of the endpoints serving them, unauthenticated endpoints can be made to execute the screens' rendering code. As coverage of the fix describes, this can be leveraged for unauthenticated (pre-auth) remote code execution on the OFBiz server, consistent with the critical 9.8 CVSS score. Any organization running Apache OFBiz 18.12.14 or earlier, especially with the OFBiz web interface exposed to the internet, is affected. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2024-08-27 amid active exploitation reports, and EPSS estimates a 99.4% probability of exploitation within 30 days.

Do: Upgrade all Apache OFBiz servers to version 18.12.15 or later immediately; the KEV listing requires applying vendor mitigations or discontinuing use within the required deadline, and newer OFBiz releases also address additional 2024 flaws (e.g., CVE-2024-45195), so updating to the latest available version is prudent. Inventory internet-facing OFBiz deployments and restrict unauthenticated access to OFBiz web endpoints where possible. Hunt for signs of exploitation (unexpected screen/view rendering requests to unauthenticated endpoints and follow-on activity on OFBiz hosts), since the flaw is being actively exploited.

9.899% KEV
  • Apache OFBiz through 18.12.14 (fixed in 18.12.15)
moderate~several thousand internet-exposed Apache OFBiz instances
Full article429 words · extracted from helpnetsecurity.com · click to collapse

CVE-2024-38856, an incorrect authorization vulnerability affecting all but the latest version of Apache OFBiz, may be exploited by remote, unauthenticated attackers to execute arbitrary code on vulnerable systems.

CVE-2024-38856

About CVE-2024-38856

Apache OFBiz is an open-source framework for enterprise resource planning (ERP) that encompasses web applications that serve common business needs, such as human resources, accounting, inventory management, customer relationship management, marketing and so on.

CVE-2024-38856 – discovered by Hasib Vhora, a senior threat researcher at SonicWall’s Capture Labs, and a slew of other security researchers – affects every Apache OFBiz version up to and including v18.12.14.

The description of the vulnerability by Apache OFBiz developer Jacques Le Roux is light on specifics, but Vhora has published a detailed technical write-up about it.

The vulnerability was discovered while he and his colleagues were analyzing how a previously patched path traversal flaw (CVE-2024-36104) could be triggered by a publicly available PoC exploit.

They found that they could abuse the override view functionality to achieve unauthenticated access to a specific endpoint by chaining it with any other endpoints that do not require authentication.

No evidence of active exploitation

According to an advisory published by the German Federal Office for Information Security (BSI), CVE-2024-38856 has a CVSS Base Score of 9.8 (critical), and Temporal Score of 8.5 (high).

“[CVE-2024-38856] exposes critical endpoints to unauthenticated threat actors using a crafted request, paving the way for remote code execution,” Vhora explained.

The fix for the flaw has been added to v18.12.15, which was released nearly a month ago, and its effectiveness has been confirmed.

Users are recommended to upgrade their installations as soon as possible, especially in view of the recent report by the SANS Internet Storm Center, which warns about attackers trying to exploit CVE-2024-32113, a path traversal vulnerability that affects OFBiz versions up to v18.12.12.

“OFBiz appears to be far less prevalent than commercial alternatives. However, just as with any other ERP system, organizations rely on it for sensitive business data, and the security of these ERP systems is critical,” noted Johannes Ullrich, Dean of Research at the SANS Technology Institute.

SonicWall says that the Apache OFBiz team came up with a fix for CVE-2024-38856 within 24 hours, and that at this time, they are unaware of any active exploitation of the flaw.

UPDATE (August 28, 2024, 02:50 a.m. ET):

A day after a PoC exploit for the flaw was published, CISA has added CVE-2024-38856 to its Known Exploited Vulnerabilities catalog.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/08/05/cve-2024-38856/