CVE-2024-32113
About
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13.
Users are recommended to upgrade to version 18.12.13, which fixes the issue.
Rainforest analyst review
A path-traversal flaw in Apache OFBiz before 18.12.13 lets an attacker manipulate a request pathname to escape the intended directory and reach restricted endpoints. On its own that is unauthorized access to protected functionality; combined with OFBiz's view-handling and screen-rendering behavior it becomes a route to executing code on the server without authenticating, following the same pattern as the broader run of OFBiz auth-bypass and RCE issues.
OFBiz is an open-source ERP and e-commerce framework, so a deployment holds order, customer, and financial data and often sits internet-facing to serve a storefront. Through 2024 a sequence of OFBiz flaws in this area was chained and actively exploited, making any exposed instance a live target. Upgrade to 18.12.13 or later, and given how readily these traversal and view-handler bugs combine into full compromise, restrict external access to the application and check exposed servers for signs of prior exploitation.
References
- http://www.openwall.com/lists/oss-security/2024/05/09/1
- https://issues.apache.org/jira/browse/OFBIZ-13006
- https://lists.apache.org/thread/w6s60okgkxp2th1sr8vx0ndmgk68fqrd
- https://ofbiz.apache.org/download.html
- https://ofbiz.apache.org/security.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-32113
Related CVEs
Frequently asked questions
What is CVE-2024-32113?
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue.
How severe is CVE-2024-32113?
CVE-2024-32113 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.
How is CVE-2024-32113 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2024-32113?
Public advisories list the following as affected: ofbiz. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2024-32113?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
