Apache OFBiz: Confused controller-view authorization logic (forced browsing) (CVE-2024-45195) | HOL Guard CVE