CVE-2024-45195: critical vulnerability in Apache OFBiz
Apache OFBiz: Confused controller-view authorization logic (forced browsing)
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Apache OFBiz has a vulnerability that allows attackers to bypass authorization checks and access restricted pages directly by crafting specific requests, even without proper permissions.
A forced browsing vulnerability in Apache OFBiz's controller-view authorization logic (CWE-425) allows unauthenticated or unprivileged attackers to directly request restricted resources by circumventing authorization controls. The vulnerability exists in versions prior to 18.12.16 and can be exploited through direct HTTP requests to protected endpoints, resulting in unauthorized access to sensitive functionality or data.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.