CVE-2024-25065

Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:*

History

05 May 2025, 21:02

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2024/02/28/10 - () http://www.openwall.com/lists/oss-security/2024/02/28/10 - Mailing List
References () https://issues.apache.org/jira/browse/OFBIZ-12887 - () https://issues.apache.org/jira/browse/OFBIZ-12887 - Issue Tracking
References () https://lists.apache.org/thread/rplfjp7ppn9ro49oo7jsrpj99m113lfc - () https://lists.apache.org/thread/rplfjp7ppn9ro49oo7jsrpj99m113lfc - Mailing List
References () https://ofbiz.apache.org/download.html - () https://ofbiz.apache.org/download.html - Product
References () https://ofbiz.apache.org/release-notes-18.12.12.html - () https://ofbiz.apache.org/release-notes-18.12.12.html - Release Notes
References () https://ofbiz.apache.org/security.html - () https://ofbiz.apache.org/security.html - Vendor Advisory
First Time Apache
Apache ofbiz
CPE cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:*

13 Feb 2025, 18:17

Type Values Removed Values Added
Summary (en) Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue. (en) Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.

Information

Published : 2024-02-29 01:44

Updated : 2025-05-05 21:02


NVD link : CVE-2024-25065

Mitre link : CVE-2024-25065

CVE.ORG link : CVE-2024-25065


JSON object : View

Products Affected

apache

  • ofbiz
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')