Vulnerability record · CVE-2024-45507 · published 4 September 2024
CVE-2024-45507: Apache OFBiz SSRF and code injection before 18.12.16
Apache · Ofbiz
Apache OFBiz before 18.12.16 is affected by a server-side request forgery flaw combined with improper control of code generation (code injection). The vendor recommends upgrading to 18.12.16, which fixes the issue. Because the flaw is network-reachable and requires no authentication or user interaction, it is a serious risk to exposed OFBiz instances.
Description
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication or interaction required, and a very high EPSS probability make this an urgent patch.
What it is
Apache OFBiz before 18.12.16 is affected by a server-side request forgery flaw combined with improper control of code generation (code injection). The vendor recommends upgrading to 18.12.16, which fixes the issue. Because the flaw is network-reachable and requires no authentication or user interaction, it is a serious risk to exposed OFBiz instances.
Impact
An unauthenticated attacker could make the server issue requests to internal or external systems and, through the code injection component, potentially execute code in the OFBiz context. This can lead to full compromise of confidentiality, integrity and availability of the application and its host.
Attack surface
Reachable over the network via HTTP against an exposed OFBiz instance, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is required.
Exploitation
The record does not list this CVE in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.93229, 99.83rd percentile), indicating a strong likelihood of exploitation activity. Reference tags include Patch and Vendor Advisory but no public exploit tag.
What to do
- Upgrade Apache OFBiz to 18.12.16 or later as the primary fix.
- If immediate upgrade is not possible, restrict network access to OFBiz management and application endpoints to trusted sources only.
- Place OFBiz behind a reverse proxy or WAF and block requests to internal/private address ranges to reduce SSRF reach.
- Monitor vendor advisories and the OFBIZ-13132 issue for any additional guidance.
- Review and harden any server-side request or code-generation functionality exposed by the application.
Detection
- Monitor OFBiz server logs for outbound requests to internal or unexpected external hosts originating from the application.
- Alert on unusual HTTP requests to OFBiz endpoints from unauthenticated or unexpected sources.
- Watch for signs of code execution or unexpected child processes spawned by the OFBiz service.
- Correlate network egress from OFBiz hosts with known internal address ranges to catch SSRF attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://issues.apache.org/jira/browse/OFBIZ-13132 | Issue TrackingPatchVendor Advisory |
| https://lists.apache.org/thread/o90dd9lbk1hh3t2557t2y2qvrh92p7wy | Mailing List |
| https://ofbiz.apache.org/download.html | Product |
| https://ofbiz.apache.org/security.html | PatchVendor Advisory |
| http://www.openwall.com/lists/oss-security/2024/09/03/7 |
Track CVE-2024-45507 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-45507), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.