CVE-2024-25065

P

ossible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.

Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:*

History

05 May 2025, 21:02

Type Values Removed Values Added
First Time Apache
Apache ofbiz
CPE cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:*
References () http://www.openwall.com/lists/oss-security/2024/02/28/10 - () http://www.openwall.com/lists/oss-security/2024/02/28/10 - Mailing List
References () https://issues.apache.org/jira/browse/OFBIZ-12887 - () https://issues.apache.org/jira/browse/OFBIZ-12887 - Issue Tracking
References () https://lists.apache.org/thread/rplfjp7ppn9ro49oo7jsrpj99m113lfc - () https://lists.apache.org/thread/rplfjp7ppn9ro49oo7jsrpj99m113lfc - Mailing List
References () https://ofbiz.apache.org/download.html - () https://ofbiz.apache.org/download.html - Product
References () https://ofbiz.apache.org/release-notes-18.12.12.html - () https://ofbiz.apache.org/release-notes-18.12.12.html - Release Notes
References () https://ofbiz.apache.org/security.html - () https://ofbiz.apache.org/security.html - Vendor Advisory

13 Feb 2025, 18:17

Type Values Removed Values Added
Summary (en) Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue. (en) Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.

21 Nov 2024, 09:00

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2024/02/28/10 - () http://www.openwall.com/lists/oss-security/2024/02/28/10 -
References () https://issues.apache.org/jira/browse/OFBIZ-12887 - () https://issues.apache.org/jira/browse/OFBIZ-12887 -
References () https://lists.apache.org/thread/rplfjp7ppn9ro49oo7jsrpj99m113lfc - () https://lists.apache.org/thread/rplfjp7ppn9ro49oo7jsrpj99m113lfc -
References () https://ofbiz.apache.org/download.html - () https://ofbiz.apache.org/download.html -
References () https://ofbiz.apache.org/release-notes-18.12.12.html - () https://ofbiz.apache.org/release-notes-18.12.12.html -
References () https://ofbiz.apache.org/security.html - () https://ofbiz.apache.org/security.html -

29 Aug 2024, 20:36

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1

Information

Published : 2024-02-29 01:44

Updated : 2025-05-05 21:02


NVD link : CVE-2024-25065

Mitre link : CVE-2024-25065

CVE.ORG link : CVE-2024-25065


JSON object : View

Products Affected
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')