The good news: I found exactly what I'd like for my local honey marketplace project

https://cwiki.apache.org/confluence/pages/viewpage.action?pageId=100828046

The bad news: It isn't a real thing, it is a description of desired functionality in Apache's OFBiz project and was last touched 7 years ago.

#ofbiz #apachefoundation #beekeeping

Marketplace (In-Progress) - OFBiz Project Open Wiki - Apache Software Foundation

#BSI WID-SEC-2024-3481: [NEU] [hoch] #Apache #OFBiz: Mehrere Schwachstellen ermöglichen Codeausführung

Ein Angreifer kann mehrere Schwachstellen in Apache OFBiz ausnutzen, um beliebigen Programmcode auszuführen.

https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3481

Warn- und Informationsdienst

Apache OFBiz Update fixes High-Severity Flaw leading to Remote Code Execution.

The Apache security team patched the vulnerability in version 18.12.16 by adding authorization checks. OFBiz users are advised to upgrade their installations as soon as possible to block potential attacks.

https://www.rapid7.com/blog/post/2024/09/05/cve-2024-45195-apache-ofbiz-unauthenticated-remote-code-execution-fixed/

#apache #ofbiz #patch #it #security #privacy #technology #engineering #tech #media #news

CVE-2024-45195: Apache OFBiz Unauthenticated Remote Code Execution (Fixed) | Rapid7 Blog

Apache OFBiz below 18.12.16 is vulnerable to CVE-2024-45195, an unauthenticated remote code execution issue that affects both Linux and Windows.

Rapid7
Apache fixed a new remote code execution flaw in Apache OFBiz

Apache addressed a remote code execution vulnerability affecting the Apache OFBiz open-source enterprise resource planning (ERP) system.

Security Affairs

#BSI WID-SEC-2024-2043: [NEU] [hoch] #Apache #OFBiz: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Apache OFBiz ausnutzen, um Sicherheitsvorkehrungen zu umgehen oder vertrauliche Informationen offenzulegen.

https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-2043

Warn- und Informationsdienst

U.S. CISA adds Apache OFBiz bug to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apache OFBiz bug to its Known Exploited Vulnerabilities catalog.

Security Affairs
CISA adds Apache OFBiz and Android kernel bugs to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apache OFBiz and Android kernel bugs to its Known Exploited Vulnerabilities catalog.

Security Affairs
Researchers warn of a new critical Apache OFBiz flaw

Researchers urge organizations using Apache OFBiz to address a critical bug, following reports of active exploitation of another flaw.

Security Affairs

CVE-2024-38856, an incorrect authorization vulnerability affecting all but the latest version of Apache OFBiz, may be exploited by remote, unauthenticated attackers to execute arbitrary code on vulnerable systems.

https://www.helpnetsecurity.com/2024/08/05/cve-2024-38856/

#Cybersecurity #OFBiz #CVE

Critical Apache OFBiz pre-auth RCE flaw fixed, update ASAP! (CVE-2024-38856) - Help Net Security

CVE-2024-38856 may be exploited by remote, unauthenticated attackers to execute arbitrary code on vulnerable systems.

Help Net Security

#BSI WID-SEC-2024-1753: [NEU] [hoch] #Apache #OFBiz: Schwachstelle ermöglicht Codeausführung

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache OFBiz ausnutzen, um beliebigen Programmcode auszuführen.

https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1753

Warn- und Informationsdienst