Sploitus

CVE-2021-29200

1 known exploit for CVE-2021-29200

Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack

Affected products
Apache Ofbiz
Apache Ofbiz
< 17.12.07
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
55.4% (99th percentile)
Weakness
CWE-502
NVD status
Modified
Published
2021-04-27

Workaround

Upgrade to at least 17.12.07 or apply one of the patches at https://issues.apache.org/jira/browse/OFBIZ-12216

CVE-2021-29200 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2021-29200

Proof-of-concept code and exploit modules indexed by Sploitus