Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin.
This issue affects Apache OFBiz: before 24.09.02 only when the scrum plugin is used.
Even unauthenticated attackers can exploit this vulnerability.
Users are recommended to upgrade to version 24.09.02, which fixes the issue.
{
"cna_assigner": "apache",
"cwe_ids": [
"CWE-94"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54466.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "24.09.02"
}
],
"source": "AFFECTED_FIELD"
},
{
"extracted_events": [
{
"fixed": "24.09.02"
}
],
"source": "DESCRIPTION"
}
]
}{
"cpe": "cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "24.09.02"
}
],
"source": "CPE_RANGE"
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54466.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "115239135110448458133838827146088054427",
"length": 4499
},
"id": "CVE-2025-54466-082710e8",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/apache/ofbiz-framework/commit/a0fd48e6f8e9f7195805d6c86281b815fb2de892",
"target": {
"file": "framework/widget/src/main/java/org/apache/ofbiz/widget/renderer/fo/ScreenFopViewHandler.java",
"function": "render"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"249146079106409486859352739705293824872",
"314012154644596642122118081014475321011",
"242468568323965799300793993567488478400",
"251410504749570407709719120966721489550"
],
"threshold": 0.9
},
"id": "CVE-2025-54466-b8194ec6",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/apache/ofbiz-framework/commit/a0fd48e6f8e9f7195805d6c86281b815fb2de892",
"target": {
"file": "framework/widget/src/main/java/org/apache/ofbiz/widget/renderer/fo/ScreenFopViewHandler.java"
}
}
]
"2026-08-12T14:52:45Z"