CVE-2024-25065

Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:*

History

05 May 2025, 21:02

Type Values Removed Values Added
First Time Apache ofbiz
Apache
CPE cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:*
References () http://www.openwall.com/lists/oss-security/2024/02/28/10 - () http://www.openwall.com/lists/oss-security/2024/02/28/10 - Mailing List
References () https://issues.apache.org/jira/browse/OFBIZ-12887 - () https://issues.apache.org/jira/browse/OFBIZ-12887 - Issue Tracking
References () https://lists.apache.org/thread/rplfjp7ppn9ro49oo7jsrpj99m113lfc - () https://lists.apache.org/thread/rplfjp7ppn9ro49oo7jsrpj99m113lfc - Mailing List
References () https://ofbiz.apache.org/download.html - () https://ofbiz.apache.org/download.html - Product
References () https://ofbiz.apache.org/release-notes-18.12.12.html - () https://ofbiz.apache.org/release-notes-18.12.12.html - Release Notes
References () https://ofbiz.apache.org/security.html - () https://ofbiz.apache.org/security.html - Vendor Advisory

13 Feb 2025, 18:17

Type Values Removed Values Added
Summary (en) Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue. (en) Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.

21 Nov 2024, 09:00

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2024/02/28/10 - () http://www.openwall.com/lists/oss-security/2024/02/28/10 -
References () https://issues.apache.org/jira/browse/OFBIZ-12887 - () https://issues.apache.org/jira/browse/OFBIZ-12887 -
References () https://lists.apache.org/thread/rplfjp7ppn9ro49oo7jsrpj99m113lfc - () https://lists.apache.org/thread/rplfjp7ppn9ro49oo7jsrpj99m113lfc -
References () https://ofbiz.apache.org/download.html - () https://ofbiz.apache.org/download.html -
References () https://ofbiz.apache.org/release-notes-18.12.12.html - () https://ofbiz.apache.org/release-notes-18.12.12.html -
References () https://ofbiz.apache.org/security.html - () https://ofbiz.apache.org/security.html -

29 Aug 2024, 20:36

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
Summary
  • (es) Posible path traversal en Apache OFBiz que permite omitir la autenticación. Se recomienda a los usuarios actualizar a la versión 18.12.12, que soluciona el problema.

29 Feb 2024, 01:44

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-29 01:44

Updated : 2025-05-05 21:02


NVD link : CVE-2024-25065

Mitre link : CVE-2024-25065

CVE.ORG link : CVE-2024-25065


JSON object : View

Products Affected

apache

  • ofbiz
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')