CVE-2024-38856
Last modified
CVE-2024-38856 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check user's permissions because they rely on the configuration of their endpoints).. CISA has confirmed active exploitation in the wild. EPSS estimates a 99.43% chance of exploitation in the next 30 days.
Description
Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check user's permissions because they rely on the configuration of their endpoints).
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Ofbiz | < 18.12.15 |
References
- https://issues.apache.org/jira/browse/OFBIZ-13128Issue Tracking
- https://lists.apache.org/thread/olxxjk6b13sl3wh9cmp0k2dscvp24l7wMailing List, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-38856Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-38856?
How severe is CVE-2024-38856?
How do I fix CVE-2024-38856?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-38831VMware Aria Operations contains a local privilege escalation…7.8
- CVE-2024-38832VMware Aria Operations contains a stored cross-site scriptin…6.4
- CVE-2024-38833VMware Aria Operations contains a stored cross-site scriptin…5.4
- CVE-2024-38834VMware Aria Operations contains a stored cross-site scriptin…4.8
- CVE-2024-3884A flaw was found in Undertow that can cause remote denial of…7.5
- CVE-2024-3885The Premium Addons for Elementor plugin for WordPress is vul…5.4
- CVE-2024-38857Improper neutralization of input in Checkmk before versions …6.1
- CVE-2024-38858Improper neutralization of input in Checkmk before version 2…6.1
- CVE-2024-38859XSS in the view page with the SLA column configured in Check…6.1
- CVE-2024-3886The tagDiv Composer plugin for WordPress is vulnerable to Re…6.1
- CVE-2024-38860Improper neutralization of input in Checkmk before versions …6.1
- CVE-2024-38861Improper Certificate Validation in Checkmk Exchange plugin M…7.4
Are you affected by CVE-2024-38856?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
