← back
CVE-2024-38856highunder attackCWE-863

Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 8.1epss 99%
from disclosure to weapon0 days
Published on NVDAug 5
1st PoCApr 10
metasploitMay 30
CISA KEV+22d
exploitation probability
99%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
21 public exploit(s)
Action required by CISAfederal deadline: 2024-09-17

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Researched and written with AI from the vendor advisory and public analysis, with the sources above. Always confirm the fixed version in the official advisory before acting.
Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check user's permissions because they rely on the configuration of their endpoints).
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.