PT-2024-4169 · Adobe · Commerce

Published

2024-06-11

·

Updated

2024-07-09

·

CVE-2024-34103

CVSS v4.0

9.2

Critical

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier
Description The issue is related to insufficient authentication procedures in Adobe Commerce, which could allow a remote attacker to escalate their privileges. This could result in unauthorized access or elevated privileges within the application. Exploitation does not require user interaction, but the attack complexity is high.
Recommendations For Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier, update to a version that includes the fix for the improper authentication vulnerability to prevent privilege escalation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04654
BIT-MAGENTO-2024-34103
CVE-2024-34103
GHSA-F7Q4-9GWV-6774

Affected Products

Commerce