High severity7.5NVD Advisory· Published Dec 26, 2023· Updated Jun 17, 2026
CVE-2023-50968
CVE-2023-50968
Description
Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations.
The same uri can be operated to realize a SSRF attack also without authorizations.
Users are recommended to upgrade to version 18.12.11, which fixes this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
6- issues.apache.org/jira/browse/OFBIZ-12875nvdIssue TrackingPatchVendor Advisory
- www.openwall.com/lists/oss-security/2023/12/26/2nvdMailing ListThird Party Advisory
- lists.apache.org/thread/x5now4bk3llwf3k58kl96qvtjyxwp43qnvdMailing ListVendor Advisory
- ofbiz.apache.org/security.htmlnvdVendor Advisory
- ofbiz.apache.org/download.htmlnvdProduct
- ofbiz.apache.org/release-notes-18.12.11.htmlnvdRelease Notes
News mentions
0No linked articles in our index yet.