By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that are reflected on the webpage; a specially crafted Freemarker template could be used for remote code execution. Mitigation: Upgrade to Apache OFBiz 16.11.01
| Software | From | Fixed in |
|---|---|---|
| apache / ofbiz | 13.07 | 13.07.x |
| apache / ofbiz | 12.04.05 | 12.04.05.x |
| apache / ofbiz | 12.04 | 12.04.x |
| apache / ofbiz | 12.04.04 | 12.04.04.x |
| apache / ofbiz | 12.04.01 | 12.04.01.x |
| apache / ofbiz | 11.04.01 | 11.04.01.x |
| apache / ofbiz | 12.04.02 | 12.04.02.x |
| apache / ofbiz | 13.07.02 | 13.07.02.x |
| apache / ofbiz | 12.04.06 | 12.04.06.x |
| apache / ofbiz | 13.07.01 | 13.07.01.x |
| apache / ofbiz | 11.04.04 | 11.04.04.x |
| apache / ofbiz | 11.04.03 | 11.04.03.x |
| apache / ofbiz | 11.04 | 11.04.x |
| apache / ofbiz | 13.07.03 | 13.07.03.x |
| apache / ofbiz | 11.04.06 | 11.04.06.x |
| apache / ofbiz | 11.04.02 | 11.04.02.x |
| apache / ofbiz | 11.04.05 | 11.04.05.x |
| apache / ofbiz | 12.04.03 | 12.04.03.x |