Security Advisory

CVE-2019-10074

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-09-11 20:38:56
Last updated 2024-08-04 22:10:09
Assigner apache
CVSS score not scored
State PUBLISHED

Description

An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This was the case for the Customer Request "story" input in the Order Manager application. Encoding should not be disabled without good reason and never within a field that accepts user input. Mitigation: Upgrade to 16.11.06 or manually apply the following commit on branch 16.11: r1858533