Vulnerability Description
Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apache OFBiz version 17.12.07 and prior versions. Upgrade to at least 17.12.08 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12297.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Ofbiz | < 17.12.08 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread.html/r164c91c47d638869c38e41b3ce501ecaa71f385939
- https://lists.apache.org/thread.html/r21f76ccb0fca2e2b236328d91b9d4b760352fae629
- https://lists.apache.org/thread.html/r23d04e9c477c3547f6cc87f11626899617927053bb
- https://lists.apache.org/thread.html/r3f1046dccb61568ca8d871f4527f274b2a531e0865
- https://lists.apache.org/thread.html/r5899ec8324d961863e162b75679309ba4ebe9dbd79
- https://lists.apache.org/thread.html/r5b7e87f970d678f819263b35b7179f0d979f5c0f71
- https://lists.apache.org/thread.html/r8d824c1491f552da820ef181b7b2d0541410b3a874
- https://lists.apache.org/thread.html/ra582196fe06566ac4dbd896223f58c379cdb38088d
- https://lists.apache.org/thread.html/radf6d421ec20c9e6d738155d380514f9ba1c9386c5
- https://lists.apache.org/thread.html/rae6c5ec2c5fc00cbc75612ab6d94a8cc0d02603228
- https://lists.apache.org/thread.html/rb4024165b7ef0428761aa0c334d44bf8bd05b53331
- https://lists.apache.org/thread.html/rc40120f33e38f51fc1036c6572094d44cb19d73aa8
- https://lists.apache.org/thread.html/rca5b167748f0d04816747d68c4ceb7afff9b7b7556
- https://lists.apache.org/thread.html/rd7d60e3276b8a9a106a6b057d3976fe123beff6c47
- https://lists.apache.org/thread.html/rdfab8e1df42888416e2705acc86b32e1ea0a03a131
FAQ
What is CVE-2021-37608?
CVE-2021-37608 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apache OFBiz version 17.12.07 and prior versions. Upgrad...
How severe is CVE-2021-37608?
CVE-2021-37608 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-37608?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Ofbiz.