diff --git a/_cases/2024/DIVD-2024-00039.md b/_cases/2024/DIVD-2024-00039.md index 28d26649..cdf0f78b 100644 --- a/_cases/2024/DIVD-2024-00039.md +++ b/_cases/2024/DIVD-2024-00039.md @@ -18,8 +18,9 @@ versions: recommendation: "Update to Apache OFBiz version 18.12.15 or higher if available" workaround: "None" patch_status: Patch available -status : Open +status : Closed start: 2024-09-29 +end: 2024-12-02 timeline: - start: 2024-09-29 end: @@ -29,14 +30,20 @@ timeline: event: "DIVD finds fingerprint, preparing to scan." - start: 2024-09-29 end: - event: "Case opened, first version of this casefile" + event: "Case opened, first version of this casefile." - start: 2024-09-29 end: event: "DIVD starts scanning the internet for vulnerable instances." - start: 2024-10-01 end: - event: "DIVD starts notifying network owners with a vulnerable instance in their network" - + event: "DIVD starts notifying network owners with a vulnerable instance in their network." +- start: 2024-10-30 + end: + event: "DIVD start notifying network owners with a vulnerable instance in their network for the second time." +- start: 2024-12-02 + end: + event: "Last scan and closing case." +ips: 45 --- ## Summary @@ -56,4 +63,4 @@ DIVD is currently working to identify parties that are running a version of Apac * {% cve CVE-2024-38856 %} * [National Vulnerability Database for CVE-2024-38856](https://nvd.nist.gov/vuln/detail/CVE-2024-38856) -* [Indepth information on CVE-2024-23692](https://www.zscaler.com/blogs/security-research/cve-2024-38856-pre-auth-rce-vulnerability-apache-ofbiz) +* [Indepth information on CVE-2024-38856](https://www.zscaler.com/blogs/security-research/cve-2024-38856-pre-auth-rce-vulnerability-apache-ofbiz)