The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code
https://lists.apache.org/thread/oj2s6objhdq72t6g29omqpcbd1wlp48o
https://lists.apache.org/thread/9tmf9qyyhgh6m052rhz7lg9vxn390bdv
https://blog.sonicwall.com/en-us/2023/12/sonicwall-discovers-critical-apache-ofbiz-zero-day-authbiz/
https://github.com/lwd3c/CVE-2026-47342
https://github.com/ismailmazumder/SL7CVELabsBuilder
https://github.com/securelayer7/SL7CVELabsBuilder
https://github.com/pulentoski/CVE-2023-51467-and-CVE-2023-49070
https://github.com/yukselberkay/CVE-2023-49070_CVE-2023-51467
https://github.com/vulncheck-oss/cve-2023-51467
https://github.com/JaneMandy/CVE-2023-51467-Exploit
https://github.com/D0g3-8Bit/OFBiz-Attack
https://github.com/jakabakos/Apache-OFBiz-Authentication-Bypass
https://github.com/Chocapikk/CVE-2023-51467
https://www.openwall.com/lists/oss-security/2023/12/26/3
https://ofbiz.apache.org/security.html
https://ofbiz.apache.org/release-notes-18.12.11.html
Published: 2023-12-26
Updated: 2024-01-04
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
EPSS: 0.96001
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Interest