CVE-2025-26865
CVE-2025-26865
Título es
CVE-2025-26865
Lun, 10/03/2025 – 14:15
Tipo
CWE-1336
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-26865
Descripción en
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: from 18.12.17 before 18.12.18.
It's a regression between 18.12.17 and 18.12.18.
In case you use something like that, which is not recommended!
For security, only official releases should be used.
In other words, if you use 18.12.17 you are still safe.
The version 18.12.17 is not a affected.
But something between 18.12.17 and 18.12.18 is.
In that case, users are recommended to upgrade to version 18.12.18, which fixes the issue.
10/03/2025
10/03/2025
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Referencias
https://issues.apache.org/jira/browse/OFBIZ-12594
https://lists.apache.org/thread/prb48ztk01bflyyjbl6p56wlcc1n5sz7
https://ofbiz.apache.org/download.html
https://ofbiz.apache.org/security.html
http://www.openwall.com/lists/oss-security/2025/03/07/1
Enviar en el boletín
Off
