CVE-2024-32113
Apache Software Foundation Apache OFBiz, apache ofbiz
Published 8 May 2024 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 7 Aug 2024, with a remediation deadline of 28 Aug 2024 for US federal agencies.
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue.
References
- www.openwall.com/lists/oss-security/2024/05/09/1 · Mailing List
- issues.apache.org/jira/browse/OFBIZ-13006 · Vendor Advisory
- lists.apache.org/thread/w6s60okgkxp2th1sr8vx0ndmgk68fqrd · Mailing List
- ofbiz.apache.org/download.html · Product
- ofbiz.apache.org/security.html · Patch
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-32113 · Third Party Advisory, US Government Resource