Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.
https://lists.apache.org/thread/rplfjp7ppn9ro49oo7jsrpj99m113lfc
https://isc.sans.edu/diary/rss/30784
https://ofbiz.apache.org/security.html
https://ofbiz.apache.org/release-notes-18.12.12.html
https://ofbiz.apache.org/download.html
https://issues.apache.org/jira/browse/OFBIZ-12887
http://www.openwall.com/lists/oss-security/2024/02/28/10
Source: Mitre, NVD
Published: 2024-02-29
Updated: 2025-05-05
Base Score: 7.5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
Severity: High
Base Score: 9.1
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity: Critical
EPSS: 0.00981