CVE-2024-45507: Apache OFBiz
Critical severity, CVSS 9.8. EPSS: 93.2% chance of exploitation in the next 30 days.
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.
Affected products
- Apache OFBiz: before 18.12.16 (fixed in 18.12.16)
Published 2024-09-04. Last modified 2026-06-17.