Skip to content

Conversation

@securestep9
Copy link
Collaborator

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the Apache OFBiz open-source enterprise resource planning (ERP) system CVE-2024-38856 to its Known Exploited Vulnerabilities ) catalog, citing evidence of active exploitation in the wild.
CVE-2024-38856 carries a score of 9.8 out of 10 on the CVSS vulnerability-severity scale, since it allows pre-authentication remote code execution (RCE). CISA's move comes after proof-of-concept (PoC) exploits were made available to the public following the flaw's disclosure in early August 2024

@securestep9 securestep9 merged commit f4b0bf8 into OWASP:master Aug 30, 2024
@securestep9 securestep9 deleted the apache_ofbiz branch August 30, 2024 23:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant