January 26, 2021

GHSL-2020-067: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Apache OfBiz

Alvaro Muñoz

Coordinated Disclosure Timeline

  • 04/13/2020: Report sent to vendor.
  • 04/23/2020: OfBiz maintainer acknowledges the issue.
  • 04/23/2020: As per Apache policy, no CVE will be issued for post-authentication vulnerabilities no matter if they are privilege escalations or XSS issues (including this one that can be triggered via XSS reported in GHSL-2020-068)
  • 01/10/2021: Addressed in 17.12.05


Apache OfBiz is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE)


Apache Ofbiz

Tested Version



Server-Side Template Injection on renderLookupField

Untrusted data flows from request.getParameter("_LAST_VIEW_NAME_") to a FreeMarker macro call definition. An attacker with privileges to render any page containing a lookup field will be able to execute arbitrary system commands by sending a payload such as:


Note that lookup fields are used in multiple modules of the backend application and they require different permissions.


This issue leads to Remote Code Execution


Not assigned


This issue was discovered and reported by GHSL team member @pwntester (Alvaro Muñoz).


You can contact the GHSL team at securitylab@github.com, please include the GHSL-2020-067 in any communication regarding this issue.