Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations. The same uri can be operated to realize a SSRF attack also without authorizations. Users are recommended to upgrade to version 18.12.11, which fixes this issue.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2023-12-26T11:45:55.393Z

Updated: 2024-08-02T22:23:44.086Z

Reserved: 2023-12-17T12:58:11.842Z

Link: CVE-2023-50968

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-12-26T12:15:07.287

Modified: 2024-01-04T03:01:53.323

Link: CVE-2023-50968

cve-icon Redhat

No data.