Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations. The same uri can be operated to realize a SSRF attack also without authorizations. Users are recommended to upgrade to version 18.12.11, which fixes this issue.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2025-02-13T17:19:42.335Z

Reserved: 2023-12-17T12:58:11.842Z

Link: CVE-2023-50968

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-12-26T12:15:07.287

Modified: 2024-11-21T08:37:38.070

Link: CVE-2023-50968

cve-icon Redhat

No data.