CVE-2024-36104: Apache OFBiz

Critical severity, CVSS 9.1. EPSS: 87.9% chance of exploitation in the next 30 days.

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.14. Users are recommended to upgrade to version 18.12.14, which fixes the issue.

Affected products

  • Apache OFBiz: before 18.12.14 (fixed in 18.12.14)

Published 2024-06-04. Last modified 2026-06-17.