Severity: High Vendor: The Apache Software Foundation
Versions Affected: OFBiz versions prior to 18.12.06 Description: The Birt viewer version 4.5.0 has a security issue that allows this exploit. We waited long for https://github.com/eclipse/birt/issues/625 to resolve but eventually decided to release OFBiz 18.12.06 without the Birt component Mitigation: Upgrade to at least 18.12.06 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-... Credit: npodoty...@ptsecurity.com References: http://ofbiz.apache.org/download.html#vulnerabilities