Description
OFBiz allows an unauthenticated attacker to send arbitrary requests to perform lookups on the internal network which is otherwise not accessible externally. An attacker may use this feature to perform SSRF (server-side request forgery) attacks on the server.
Remediation
Upgrade to the latest version of OFBiz
References
Related Vulnerabilities
Envoy Proxy Insufficient Verification of Data Authenticity Vulnerability (CVE-2020-8660)
MySQL CVE-2019-2814 Vulnerability (CVE-2019-2814)
MySQL CVE-2017-3652 Vulnerability (CVE-2017-3652)
Oracle Database Server CVE-2019-2909 Vulnerability (CVE-2019-2909)
Mailman Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2006-4624)