Uploaded image for project: 'OFBiz'
  1. OFBiz
  2. OFBIZ-1525 Issue to group security concerns
  3. OFBIZ-12558

Possible authenticated attack related to Tomcat CVE-2020-1938

    XMLWordPrintableJSON

Details

    • Sub-task
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 18.12.05, Upcoming Branch
    • 18.12.06, 22.01.01
    • None
    • None
    • Bug Crush Event - 21/2/2015

    Description

      Lion Tree <liontree0110@gmail.com> has reported us that "CVE-2020-1938 is not fully fixed".

      Though it was fixed by OFBIZ-11407, it still possible for an authenticated user to upload a webshell included in an image using one of the OFBiz upload possibilities. That of course is not new and already covered by OFBIZ-12080 "Secure the uploads", but was still incomplete.

      So this Jira covers 2 points:

      1. Disable bypass of Tomcat due to setting in framework/catalina/ofbiz-component.xml
      2. Enforce upload prevention of webshells, specifically but not only those included in images

      Attachments

        Activity

          People

            jleroux Jacques Le Roux
            jleroux Jacques Le Roux
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: