CVE-2024-38856 is an incorrect authorization vulnerability in Apache OFBiz affecting versions through 18.12.14. The flaw allows unauthenticated access to screen rendering functionality when endpoint-level assumptions about access control are relied upon but the underlying screen definitions do not explicitly enforce permission checks. Apache indicated that unauthenticated endpoints could permit execution of screen rendering code if certain preconditions are met, creating a path to unauthorized execution of server-side functionality. Reporting and exploitation activity associated with this issue indicate that it can be leveraged for unauthenticated remote code execution on vulnerable OFBiz servers, and it has been described as related to or bypassing prior OFBiz fixes for similar authorization flaws.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
7 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a Python exploit script (Apache_bang.py) targeting CVE-2024-38856, a critical unauthenticated remote code execution vulnerability in Apache OFBiz versions up to 18.12.14. The exploit works by sending a specially crafted Groovy payload (containing a base64-encoded shell command) to the /webtools/control/main/ProgramExport endpoint, which is accessible without authentication on vulnerable systems. The script supports both scanning (using ping, wget, curl to a supplied domain) and exploitation (executing arbitrary shell commands and retrieving their output). The README provides background on the vulnerability, affected versions, and usage instructions, including example commands. The code is operational and allows for flexible command execution, but does not include weaponized features such as automated post-exploitation or persistence. The only code file is Apache_bang.py, which is the main entry point. No hardcoded IPs or domains are present, but the endpoint path is fingerprintable. The repository is intended for research and defensive purposes, as stated in the README.
This repository contains a Python exploit script (exploit.py) targeting Apache OFBiz versions prior to 18.12.15, specifically exploiting CVE-2024-38856. The exploit leverages an incorrect authorization vulnerability in the /webtools/control/forgotPassword/ProgramExport endpoint, allowing unauthenticated remote code execution via Groovy code injection. The script provides two main capabilities: executing arbitrary Linux commands on the target server and establishing a reverse shell using busybox/nc. The payload is encoded as Unicode escape sequences and sent as a POST parameter. The script supports proxying, colored output, and intelligent response parsing. The README.md provides usage instructions and a description of the vulnerability. The main entry point is exploit.py, which is a standalone exploit and not part of a larger framework.
This repository contains a single Metasploit module targeting Apache OFBiz, specifically exploiting two vulnerabilities: CVE-2024-32113 (path traversal leading to RCE) and CVE-2024-38856 (incorrect authorization allowing RCE without traversal). The exploit works by sending a POST request to the /webtools/control/forgotPassword/ProgramExport endpoint, injecting Groovy code that executes arbitrary OS commands. The module supports both Linux and Windows targets, with payloads tailored for each platform. The exploit is operational, providing remote code execution as the user running the OFBiz application, and can result in root access in certain configurations (e.g., Docker). The code is written in Ruby and is structured as a standard Metasploit module, with clear entry points and payload handling. The main fingerprintable endpoints are the OFBiz web application paths and the use of the local Host header. The module is suitable for use in penetration testing and red teaming against vulnerable OFBiz deployments.
This repository contains a Python exploit script (CVE-2024-38856.py) targeting Apache OFBiz versions up to 18.12.14, exploiting CVE-2024-38856, a pre-authentication remote code execution (RCE) vulnerability. The exploit works by sending a specially crafted Groovy payload to the /webtools/control/main/ProgramExport endpoint, which is accessible without authentication. The script supports two main modes: executing arbitrary shell commands (cmd mode) and establishing a reverse shell (shell mode) to an attacker-controlled host and port. The payload is encoded in Unicode escape sequences to bypass input filters. The repository includes a README with usage instructions, a requirements.txt for dependencies (requests library), and a license file. The exploit is operational and can be used to gain remote command execution or a shell on vulnerable Apache OFBiz instances.
This repository contains a Python-based exploit for CVE-2024-38856, a remote code execution vulnerability in Apache OFBiz up to version 18.12.14. The main file, 'cve-2024-38856_Scanner.py', allows an attacker to send arbitrary shell commands to a vulnerable OFBiz instance via the '/webtools/control/main/ProgramExport' endpoint. The script encodes the attacker's command in base64, wraps it in a Groovy script payload, and sends it as a POST request. The exploit supports both single-target and multi-target modes (via a file), and can automate scanning using common network commands (ping, curl, wget) against a specified domain. The README provides a brief description and ethical use warning. The exploit is operational, providing real remote code execution if the target is vulnerable. No hardcoded IPs or domains are present, but the attacker can specify a domain for scanning. The repository is focused and contains only the exploit script and a README.
This repository provides a Python-based scanner and exploit for CVE-2024-38856, a remote code execution (RCE) vulnerability in Apache OFBiz through version 18.12.14. The main script, 'cve-2024-38856_Scanner.py', can operate in two modes: scan and exploit. In scan mode, it checks if a target is vulnerable by sending commands (ping, wget, curl) that cause the target to interact with an attacker-controlled domain, confirming code execution. In exploit mode, it allows the user to execute arbitrary system commands on the target server and retrieve their output. The exploit works by sending a specially crafted Groovy payload (encoded in Unicode) to the '/webtools/control/main/ProgramExport' endpoint of the target OFBiz instance. The script supports single and batch target modes, proxying, and output to file. The repository includes a README with detailed usage instructions and a requirements.txt for dependencies. The exploit is operational, providing real command execution and output retrieval, and is not part of a larger framework.
This repository contains a Python exploit script (CVE-2024-38856.py) targeting the Apache OFBiz application for CVE-2024-38856, a remote code execution (RCE) vulnerability. The script allows an attacker to send specially crafted HTTP POST requests to several known vulnerable endpoints within the OFBiz application, injecting a Groovy payload that executes arbitrary shell commands on the server. The payload is base64-encoded and unicode-escaped to bypass input filters, and is executed via the Groovy .execute() method. The script supports multithreading, batch targeting via a file, and can perform basic scan operations using commands like ping, curl, and wget. The README.md provides usage instructions and describes the script's features. The requirements.txt lists the necessary Python dependencies. The main attack vector is network-based, exploiting HTTP endpoints exposed by Apache OFBiz. The script is operational and can be used to achieve remote code execution if the target is vulnerable.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A specific OFBiz-related vulnerability identified as CVE-2024-38856; the content is about correcting a CVE ID mismatch in a template.
Apache OFBizの脆弱性で、CVE-2024-36104のパストラバーサル対策をバイパスし、認証なしのリモートコード実行につながる恐れがある重要な脆弱性。本文ではこの脆弱性を狙った攻撃観測について述べている。
Earlier Apache OFBiz issue in the same desynchronization family; reported as actively exploited in the wild.
A previously patched Apache OFBiz vulnerability referenced as one of three earlier flaws bypassed by CVE-2024-45195.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.