CISA Known Exploited Vulnerability (KEV)
Apache OFBiz Path Traversal Vulnerability
August 7, 2024
August 28, 2024
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13.
Users are recommended to upgrade to version 18.12.13, which fixes the issue.
References
Weakness Enumeration
CWE-ID | CWE Name |
---|---|
CWE-22 |
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) |