CVE-2019-10074
Last modified
CVE-2019-10074 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This was the case for the Customer Request "story" input in the Order Manager application. EPSS estimates a 3.39% chance of exploitation in the next 30 days.
Description
An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This was the case for the Customer Request "story" input in the Order Manager application. Encoding should not be disabled without good reason and never within a field that accepts user input. Mitigation: Upgrade to 16.11.06 or manually apply the following commit on branch 16.11: r1858533
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Ofbiz | >= 16.11.01, <= 16.11.05 |
References
- https://s.apache.org/r49vwMailing List, Vendor Advisory
- https://s.apache.org/r49vwMailing List, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-10074?
How severe is CVE-2019-10074?
How do I fix CVE-2019-10074?
Are you affected by CVE-2019-10074?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
