Missing Authentication in Apache Software Foundation Apache OFBiz when using the Solr plugin. This issue affects Apache OFBiz: before 18.12.09. Users are recommended to upgrade to version 18.12.09
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://ofbiz.apache.org/download.html | mitigation product |
https://ofbiz.apache.org/security.html | patch vendor advisory related |
https://ofbiz.apache.org/release-notes-18.12.09.html | release notes |
https://lists.apache.org/thread/mm5j0rsbl22q7yb0nmb6h2swbfjbwv99 | patch vendor advisory mailing list |