CVE-2024-25065

Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:*

History

05 May 2025, 21:02

Type Values Removed Values Added
First Time Apache
Apache ofbiz
CPE cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:*
References () http://www.openwall.com/lists/oss-security/2024/02/28/10 - () http://www.openwall.com/lists/oss-security/2024/02/28/10 - Mailing List
References () https://issues.apache.org/jira/browse/OFBIZ-12887 - () https://issues.apache.org/jira/browse/OFBIZ-12887 - Issue Tracking
References () https://ofbiz.apache.org/security.html - () https://ofbiz.apache.org/security.html - Vendor Advisory
References () https://ofbiz.apache.org/release-notes-18.12.12.html - () https://ofbiz.apache.org/release-notes-18.12.12.html - Release Notes
References () https://lists.apache.org/thread/rplfjp7ppn9ro49oo7jsrpj99m113lfc - () https://lists.apache.org/thread/rplfjp7ppn9ro49oo7jsrpj99m113lfc - Mailing List
References () https://ofbiz.apache.org/download.html - () https://ofbiz.apache.org/download.html - Product

13 Feb 2025, 18:17

Type Values Removed Values Added
Summary Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue. Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.

29 Feb 2024, 01:44

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-29 01:44

Updated : 2025-05-05 21:02


NVD link : CVE-2024-25065

Mitre link : CVE-2024-25065


JSON object : View

Products Affected

apache

  • ofbiz
CWE

No CWE.