Uploaded image for project: 'OFBiz'
  1. OFBiz
  2. OFBIZ-1525 Issue to group security concerns
  3. OFBIZ-11871

Server-Side Template Injection using Static

    XMLWordPrintableJSON

Details

    • Sub-task
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 17.12.03
    • 17.12.05, 18.12.01
    • ALL COMPONENTS
    • None
    • Bug Crush Event - 21/2/2015

    Description

      Alvaro Munoz <pwntester@github.com> from the GitHub Security Lab (securitylab@github.com) reported a Server-Side Template Injection that uses "Static" to the OFBiz security team, and we thank him for that.

      I'll later quote here his email message when the vulnerability will be fixed. It's a post-auth vulnerability so we did not ask for a CVE.

      Note: this vulnerabitly leads to Remote Code Execution (RCE)

      Attachments

        Activity

          People

            jleroux Jacques Le Roux
            jleroux Jacques Le Roux
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: