
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-32113 is a critical path traversal vulnerability affecting Apache OFBiz versions before 18.12.13. The vulnerability was discovered in April 2024 and publicly disclosed on May 8, 2024. This vulnerability allows attackers to execute arbitrary commands through specially crafted requests to the Apache OFBiz open-source enterprise resource planning (ERP) system (Apache Security, NVD).
The vulnerability is classified as an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. It has received a CVSS v3.1 base score of 9.8 (Critical), with attack vector being Network, attack complexity Low, requiring no privileges or user interaction. The vulnerability arises from a fragmented state between the application's current controller and view map due to different parsing methods for incoming URI patterns (Cyble Blog).
The vulnerability enables attackers to execute arbitrary commands on affected systems, potentially leading to complete system compromise. Successful exploitation allows unauthorized access and the ability to execute arbitrary commands on the server, potentially exposing sensitive information and compromising system integrity (NVD, Cyble Blog).
The vulnerability has been confirmed to be actively exploited in the wild. On August 7, 2024, CISA added CVE-2024-32113 to its Known Exploited Vulnerabilities Catalog, indicating active exploitation. The exploitation occurs when an attacker submits a crafted request to the endpoint /webtools/control/forgotPassword;/ProgramExport, enabling arbitrary command execution (CISA Alert).
Users are strongly recommended to upgrade to Apache OFBiz version 18.12.13 or later, which contains the fix for this vulnerability. The fix was implemented with commits b3b87d98dd and ff316b6e22. Additional security measures include configuring and deploying a Web Application Firewall (WAF) to filter and monitor HTTP requests, and applying the principle of least privilege to limit potential impact (Apache Security, Cyble Blog).
The vulnerability has garnered significant attention from the security community, particularly after being added to CISA's Known Exploited Vulnerabilities Catalog. CISA has set a remediation date of August 28, 2024, for federal agencies to address this vulnerability, highlighting its critical nature (CISA Alert).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."