Critical
CVE-2023-51467
PUBLISHEDApache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability
Not yet in CISA KEV
- Vendor
- Apache Software Foundation
- Product
- Apache OFBiz
- Published
- Dec 26, 2023
- EPSS
- —
Automate This Intelligence with the Pro API
Everything on this page — CVSS, EPSS, exploit status, PoCs, scanner integrations, mentions, tags, and immediate honeypot data — is available programmatically for VM, SOC, and CTI workflows.
Description
The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code
CVSS Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Status
Exploited in the wild
Recorded 2026-06-08 00:00:00 UTC · The Shadowserver (via CIRCL)
Proof of concept available
Recorded 2023-12-29 15:01:46 UTC · GitHub
References
- https://ofbiz.apache.org/download.html
- https://ofbiz.apache.org/security.html
- https://ofbiz.apache.org/release-notes-18.12.11.html
- https://issues.apache.org/jira/browse/OFBIZ-12873
- https://lists.apache.org/thread/9tmf9qyyhgh6m052rhz7lg9vxn390bdv
- https://lists.apache.org/thread/oj2s6objhdq72t6g29omqpcbd1wlp48o
- https://www.openwall.com/lists/oss-security/2023/12/26/3
Known Exploited Vulnerability Sources
Catalogues that list this CVE as a known exploited vulnerability.
| Source | Added |
|---|---|
| The Shadowserver (via CIRCL) First | 2025-06-30 00:00 UTC |
Scanner Integrations
| Scanner | Reference | Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/apache_ofbiz_deserialization.rb | Apr 28, 2025 |
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-51467.yaml | Apr 25, 2025 |
Potential Proof of Concepts
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2024-01-06 04:07:07 UTC · 38 stars
Apache Ofbiz CVE-2023-51467 图形化漏洞利用工具
github · Created 2023-12-29 17:47:54 UTC · 11 stars
A PoC exploit for CVE-2023-51467 - Apache OFBiz Authentication Bypass
github · Created 2023-12-29 15:01:46 UTC · 11 stars
Apache OfBiz Auth Bypass Scanner for CVE-2023-51467
nuclei · Created Unknown
Timeline
-
Added to KEVIntel
-
Detected by Metasploit
-
Detected by Nuclei
-
Proof of Concept Exploit Available
-
CVE Published to Public
-
CVE ID Reserved