← Back

CVE-2025-54466

nvd nist
Published: Aug 15, 2025Modified: Nov 4, 2025

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Apache OFBiz: before 24.09.02 only when the scrum plugin is used. Even unauthenticated attackers can exploit this vulnerability. Users are recommended to upgrade to version 24.09.02, which fixes the issue.

Affected (1)

Products: Apache: Ofbiz
1 product
Ofbiz
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 24.09.02

References (6)

Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Product
Source: security@apache.org
Release Notes
Source: security@apache.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.