Description
OFBiz has a authentication bypass vulnerability leading to RCE. An attacker can bypass the authentication with a specially crafted HTTP request and get full access to the system.
Remediation
Upgrade to the latest version of OFBiz
References
[SECURITY] (CVE-2024-32113) Path traversal leading to RCE
CVE-2024-45195: Apache OFBiz Unauthenticated Remote Code Execution (Fixed)