CVE-2019-12425: Apache OFBiz
High severity, CVSS 7.5. EPSS: 4.8% chance of exploitation in the next 30 days.
Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host
Affected products
- Apache OFBiz: version 17.12.01 only
Published 2020-04-30. Last modified 2026-06-17.