Apache OFBiz: Path traversal allowing authentication bypass.
Description
Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Path traversal in Apache OFBiz allows authentication bypass; upgrade to version 18.12.12.
Vulnerability
A path traversal vulnerability exists in Apache OFBiz's hasBasePermission method within LoginWorker. The contextPath parameter is not normalized, allowing an attacker to bypass authentication checks. Affected versions are Apache OFBiz before 18.12.12 [1][2][4].
Exploitation
An attacker can send a crafted HTTP request with a malicious contextPath (e.g., containing directory traversal sequences like ../) to bypass authentication. No prior authentication or special network position is required; the vulnerability is exploitable remotely [4].
Impact
Successful exploitation allows an attacker to bypass authentication mechanisms, gaining unauthorized access to OFBiz instances. This can lead to full compromise of the application, including data disclosure and potential admin-level access [1][4].
Mitigation
Users should upgrade to Apache OFBiz version 18.12.12 (released February 2024) which fixes the issue. No workarounds are available. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog as of the publication date [2][4].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- lists.apache.org/thread/rplfjp7ppn9ro49oo7jsrpj99m113lfcmitrevendor-advisory
- issues.apache.org/jira/browse/OFBIZ-12887mitreissue-tracking
- ofbiz.apache.org/download.htmlmitremitigation
- ofbiz.apache.org/release-notes-18.12.12.htmlmitrerelease-notes
- ofbiz.apache.org/security.htmlmitrerelated
- www.openwall.com/lists/oss-security/2024/02/28/10mitre
News mentions
0No linked articles in our index yet.