Active Exploitation of Apache OFBiz Zero-day Vulnerability
A critical zero-day vulnerability in Apache OFBiz is currently under wide-spread exploitation
Summary
A critical zero-day vulnerability in Apache OFBiz is currently under wide-spread exploitation
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Apache have released a security update addressing a critical zero-day vulnerability in Apache OFBiz.
The vulnerability referred to as CVE-2023-51467 has a CVSSv3 score of 9.8. Successful exploitation could allow an attacker to circumvent authentication processes, enabling them to remotely execute arbitrary code, meaning they can access and expose sensitive information.
Exploitation of CVE-2023-51467
SonicWall researchers have observed mass exploitation attempts of CVE-2023-51467 as a zero-day vulnerability.
Proof-of-concept exploit code is publicly available for CVE-2023-51467
Threat updates
| Date | Update |
|---|---|
| 12 Jan 2024 |
Proof-of-concept code publicly available
This cyber alert has been updated to reflect this change |
Remediation advice
Affected organisations are encouraged to review the Apache OFBiz Security Update and apply any relevant updates.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 12 January 2024 2:00 pm