CVE-2024-38856
Aug. 5, 2024, 12:41 p.m.
Tags
Product(s) Impacted
Apache OFBiz
- through 18.12.14
Description
Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check user's permissions because they rely on the configuration of their endpoints).
Weaknesses
CWE-863
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CWE ID: 863Date
Published: Aug. 5, 2024, 9:15 a.m.
Last Modified: Aug. 5, 2024, 12:41 p.m.
Status : Undergoing Analysis
CVE has been recently published to the CVE List and has been received by the NVD.
More infoSource
security@apache.org