Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin.
This issue affects Apache OFBiz: before 24.09.02 only when the scrum plugin is used.
Even unauthenticated attackers can exploit this vulnerability.
Users are recommended to upgrade to version 24.09.02, which fixes the issue.
References
Link | Resource |
---|---|
https://issues.apache.org/jira/browse/OFBIZ-13276 | Patch |
https://lists.apache.org/thread/14d0yd9co9gx2mctd3vyz1cc8d39n915 | Mailing List Third Party Advisory |
https://ofbiz.apache.org/download.html | Product |
https://ofbiz.apache.org/release-notes-24.09.02.html | Release Notes |
https://ofbiz.apache.org/security.html | Vendor Advisory |
Configurations
History
21 Aug 2025, 18:56
Type | Values Removed | Values Added |
---|---|---|
References | () https://issues.apache.org/jira/browse/OFBIZ-13276 - Patch | |
References | () https://lists.apache.org/thread/14d0yd9co9gx2mctd3vyz1cc8d39n915 - Mailing List, Third Party Advisory | |
References | () https://ofbiz.apache.org/download.html - Product | |
References | () https://ofbiz.apache.org/release-notes-24.09.02.html - Release Notes | |
References | () https://ofbiz.apache.org/security.html - Vendor Advisory | |
First Time |
Apache ofbiz
Apache |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
CPE | cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:* |
18 Aug 2025, 20:16
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
15 Aug 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.3 |
15 Aug 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-15 15:15
Updated : 2025-08-21 18:56
NVD link : CVE-2025-54466
Mitre link : CVE-2025-54466
CVE.ORG link : CVE-2025-54466
JSON object : View
Products Affected
apache
- ofbiz
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')