Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Updated casefile DIVD-2024-00039 #883

Merged
merged 4 commits into from
Dec 3, 2024
Merged
Changes from 3 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 12 additions & 5 deletions _cases/2024/DIVD-2024-00039.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,8 +18,9 @@ versions:
recommendation: "Update to Apache OFBiz version 18.12.15 or higher if available"
workaround: "None"
patch_status: Patch available
status : Open
status : Closed
start: 2024-09-29
end: 2024-12-2
WesselDIVD marked this conversation as resolved.
Show resolved Hide resolved
timeline:
- start: 2024-09-29
end:
Expand All @@ -29,14 +30,20 @@ timeline:
event: "DIVD finds fingerprint, preparing to scan."
- start: 2024-09-29
end:
event: "Case opened, first version of this casefile"
event: "Case opened, first version of this casefile."
- start: 2024-09-29
end:
event: "DIVD starts scanning the internet for vulnerable instances."
- start: 2024-10-01
end:
event: "DIVD starts notifying network owners with a vulnerable instance in their network"

event: "DIVD starts notifying network owners with a vulnerable instance in their network."
- start: 2024-10-30
end:
event: "DIVD start notifying network owners with a vulnerable instance in their network for the second time."
- start: 2024-12-02
end:
event: "Last scan and closing case."
ips: 45
---

## Summary
Expand All @@ -56,4 +63,4 @@ DIVD is currently working to identify parties that are running a version of Apac

* {% cve CVE-2024-38856 %}
* [National Vulnerability Database for CVE-2024-38856](https://nvd.nist.gov/vuln/detail/CVE-2024-38856)
* [Indepth information on CVE-2024-23692](https://www.zscaler.com/blogs/security-research/cve-2024-38856-pre-auth-rce-vulnerability-apache-ofbiz)
* [Indepth information on CVE-2024-38856](https://www.zscaler.com/blogs/security-research/cve-2024-38856-pre-auth-rce-vulnerability-apache-ofbiz)
Loading