[jira] [Updated] (OFBIZ-13006) [SECURITY] (CVE-2024-32113) Path traversal leading to RCE

2024-05-08 Thread Jacques Le Roux (Jira)


 [ 
https://issues.apache.org/jira/browse/OFBIZ-13006?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Jacques Le Roux updated OFBIZ-13006:

Parent: OFBIZ-1525
Issue Type: Sub-task  (was: Bug)

> [SECURITY] (CVE-2024-32113) Path traversal leading to RCE
> -
>
> Key: OFBIZ-13006
> URL: https://issues.apache.org/jira/browse/OFBIZ-13006
> Project: OFBiz
>  Issue Type: Sub-task
>  Components: framework/webapp
>Affects Versions: 18.12.13
>Reporter: Jacques Le Roux
>Assignee: Jacques Le Roux
>Priority: Critical
> Fix For: 18.12.13
>
>
> Some URLs need to be rejected before they create problems



--
This message was sent by Atlassian Jira
(v8.20.10#820010)


[jira] [Updated] (OFBIZ-13006) [SECURITY] (CVE-2024-32113) Path traversal leading to RCE

2024-05-08 Thread Jacques Le Roux (Jira)


 [ 
https://issues.apache.org/jira/browse/OFBIZ-13006?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Jacques Le Roux updated OFBIZ-13006:

Summary: [SECURITY] (CVE-2024-32113) Path traversal leading to RCE  (was: 
Reject wrong URLs)

> [SECURITY] (CVE-2024-32113) Path traversal leading to RCE
> -
>
> Key: OFBIZ-13006
> URL: https://issues.apache.org/jira/browse/OFBIZ-13006
> Project: OFBiz
>  Issue Type: Bug
>  Components: framework/webapp
>Affects Versions: 18.12.13
>Reporter: Jacques Le Roux
>Assignee: Jacques Le Roux
>Priority: Critical
> Fix For: 18.12.13
>
>
> Some URLs need to be rejected before they create problems



--
This message was sent by Atlassian Jira
(v8.20.10#820010)


[jira] [Updated] (OFBIZ-13006) [SECURITY] (CVE-2024-32113) Path traversal leading to RCE

2024-05-08 Thread Jacques Le Roux (Jira)


 [ 
https://issues.apache.org/jira/browse/OFBIZ-13006?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Jacques Le Roux updated OFBIZ-13006:

Priority: Critical  (was: Minor)
 Summary: [SECURITY] (CVE-2024-32113)  Path traversal leading to RCE   
(was: Reject wrong URLs)

> [SECURITY] (CVE-2024-32113)  Path traversal leading to RCE 
> ---
>
> Key: OFBIZ-13006
> URL: https://issues.apache.org/jira/browse/OFBIZ-13006
> Project: OFBiz
>  Issue Type: Bug
>  Components: framework/webapp
>Affects Versions: 18.12.13
>Reporter: Jacques Le Roux
>Assignee: Jacques Le Roux
>Priority: Critical
> Fix For: 18.12.13
>
>
> Some URLs need to be rejected before they create problems



--
This message was sent by Atlassian Jira
(v8.20.10#820010)