{"id":"CVE-2024-36104","summary":"Apache OFBiz: Path traversal leading to a RCE","details":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.14.\n\nUsers are recommended to upgrade to version 18.12.14, which fixes the issue.","modified":"2026-08-12T03:51:30.969813717Z","published":"2024-06-04T07:25:07.746Z","database_specific":{"cna_assigner":"apache","cwe_ids":["CWE-22"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/36xxx/CVE-2024-36104.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"fixed":"18.12.14"}]},{"extracted_events":[{"fixed":"18.12.14"}],"source":"DESCRIPTION"}]},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2024/06/03/1"},{"type":"WEB","url":"https://ofbiz.apache.org/download.html"},{"type":"WEB","url":"https://ofbiz.apache.org/security.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/36xxx/CVE-2024-36104.json"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/sv0xr8b1j7mmh5p37yldy9vmnzbodz2o"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-36104"},{"type":"REPORT","url":"https://issues.apache.org/jira/browse/OFBIZ-13092"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/ofbiz-framework","events":[{"introduced":"0"},{"fixed":"cb8c65124bca100b109f3cd1f7008a32239f3255"}],"database_specific":{"cpe":"cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"18.12.14"}],"source":"CPE_RANGE"}}],"versions":["release18.12.13","release18.12.12","release18.12.05","release18.12.04","release18.12.03","release18.12.02","release18.12.01"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-36104.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}