CERT-In Vulnerability Note
CIVN-2024-0001
Server-Side Request Forgery Vulnerability in Apache OFBiz
Original Issue Date:January 03, 2024
Severity Rating: CRITICAL
Software Affected
- Apache OFBIZ versions prior to 18.12.10.
Overview
A Server-Side Request Forgery (SSRF) vulnerability has been reported in Apache OFBiz, which could be exploited by a remote attacker to bypass implemented security restrictions on the targeted system.
Description
The vulnerability exists in Apache OFBiz due to improper authentication validation. By sending a specially crafted request, an attacker could exploit this vulnerability to conduct SSRF attack to execute arbitrary code.
Successful exploitation of this vulnerability could allow a remote attacker to perform Server-Side Request Forgery (SSRF) attacks, leading to security restriction bypass on the targeted system.
Solution
Apply appropriate software fixes as available on the vendor website:
https://ofbiz.apache.org/download.html
Vendor Information
Apache OFBiz
https://ofbiz.apache.org/
References
Apache OFBiz
https://blog.sonicwall.com/en-us/2023/12/sonicwall-discovers-critical-apache-ofbiz-zero-day-authbiz/
CVE Name
CVE-2023-51467
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|