← Back to browse · API

CVE-2024-25065

Severity
CRITICAL
CVSS
9.1
EPSS
0.47667
Risk score
53.08
CISA KEV
No
PoC
No
Published
2024-02-28
Modified
2025-02-13
First seen
2026-08-07
Aliases
EUVD-2024-22427, GHSA-3VG3-G88W-VJGF
Products
Apache Software Foundation:Apache OFBiz, Apache Software Foundation:Apache OFBiz 0 <18.12.12
Sources
euvd EUVD-2024-22427

Description

Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.

References