CISA adds Apache OFBiz and Android kernel bugs to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-32113 | Critical Unauthenticated Path Traversal in Apache OFBiz Apache OFBiz before 18.12.13 contains a path traversal vulnerability (CWE-22) in which improper limitation of a pathname allows access to restricted directories outside the intended scope. Per the CVSS vector (AV:N/AC:L/PR:N/UI:N), the flaw can be triggered remotely by an unauthenticated attacker with no user interaction. Successful exploitation has high impact on confidentiality, integrity, and availability: an attacker can reach files and directories that should be restricted, and the critical 9.8 score indicates potential full compromise of the affected server. Any organization running an affected version of the open-source Apache OFBiz ERP/enterprise automation suite is exposed. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-08-07, and EPSS assigns a 99.4% probability of exploitation within 30 days (100th percentile), amid a wave of critical OFBiz flaws patched in 2024. Do: Upgrade all Apache OFBiz instances to version 18.12.13 or later immediately, per the vendor fix and CISA KEV required action. Because the flaw is under active exploitation, prioritize any OFBiz servers exposed to the internet, hunt for signs of compromise on unpatched systems, and restrict network access to OFBiz until patched. | 9.8 | 99% | KEV |
| moderateseveral thousand internet-exposed OFBiz instances (estimate, on the order of 10^3) | |
| CVE-2024-36971 | Use-after-free in Linux kernel network dst cache (CVE-2024-36971), exploited on Android CVE-2024-36971 is a use-after-free (CWE-416) race condition in the Linux kernel networking stack: __dst_negative_advice() clears a socket's cached destination (sk->sk_dst_cache) in the wrong order relative to RCU rules and dst_release(), which can free the destination entry while it is still referenced. The bug is reachable through UDP socket operations, and CISA catalogs the impact as remote code execution in the affected kernel (Android Kernel), although the published CVSS 3.1 vector scores a local attack vector (7.8 High, AV:L). An attacker who triggers the race gains code execution in kernel context, meaning on Android a malicious app could potentially escape its sandbox and take full control of the device, with high impact on confidentiality, integrity, and availability. Affected systems include Android devices running vulnerable kernels and Linux-based systems listed in the CPE data (upstream Linux kernel and Debian Linux), with no specific vulnerable version ranges disclosed in the available data. The flaw is being actively exploited: Google warned of in-the-wild exploitation (the issue was tracked by researcher Clement Lecigne), CISA added it to the Known Exploited Vulnerabilities catalog on 2024-08-07, and EPSS estimates a ~2.7% probability of exploitation in the next 30 days; no public PoC is known. Do: Install Android security updates from Google and device OEMs (Google has already shipped patches) and verify your device's security patch level is current. Debian and other Linux users should update kernel packages to builds containing the upstream fix for the __dst_negative_advice() race. Because CISA added this to KEV on 2024-08-07 with active exploitation, apply vendor mitigations promptly or discontinue use if mitigations are unavailable. | 7.8 | 3% | KEV |
| masson the order of billions of Android devices potentially affected pre-patch (upper bound), plus a large installed base across Linux/Debian systems |
Full article251 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apache OFBiz and Android kernel bugs to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Android Kernel Remote Code Execution flaw (CVE-2024-36971) and an Apache OFBiz Path Traversal issue (CVE-2024-32113) to its Known Exploited Vulnerabilities (KEV) catalog.
Below are the descriptions of the two flaws:
- CVE-2024-36971 is a remote code execution vulnerability impacting the Android kernel. The vulnerability was discovered by Clement Lecigne of Google’s Threat Analysis Group (TAG). The TAG team investigates attacks carried out by nation-state actors and commercial spyware vendors. The IT giant is aware that the vulnerability has been actively exploited in the wild. The company did not share details of the attacks exploiting this vulnerability.
- CVE-2024-32113 is a path traversal issue in the Apache OFBiz. The exploitation of this vulnerability could lead to remote command execution. Researchers from SANS recently observed a surge in the attacks targeting CVE-2024-32113.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix this vulnerability by August 28, 2024.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Known Exploited Vulnerabilities Catalog)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/166782/hacking/cisa-adds-apache-ofbiz-and-android-kernel-bugs-known-exploited-vulnerabilities-catalog.html