CVE-2024-32113 is a critical path traversal vulnerability (CWE-22) affecting Apache OFBiz versions prior to 18.12.13. This flaw allows unauthenticated remote attackers to achieve full compromise of affected systems, including arbitrary code execution, with a CVSS score of 9.8 (CRITICAL). The vulnerability is actively exploited in the wild, with public exploit code available in Metasploit and Nuclei templates, and has garnered significant community and media attention. Organizations using Apache OFBiz are strongly advised to upgrade to version 18.12.13 immediately to mitigate this severe risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 18.12.13CPE matchmatch criteria | cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:* | ||
>= 0, < 18.12.13CPE match | cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.