PT-2024-6960 · Adobe · Magento Open Source+1
Published
2024-10-08
·
Updated
2024-10-13
·
CVE-2024-45124
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier
Magento Open Source versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier
Description
The issue is related to insufficient access control in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source, allowing a remote attacker to bypass security restrictions. This could result in a security feature bypass, with a low impact on integrity. Exploitation of this issue does not require user interaction.
Recommendations
For Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier: Update to a version that includes the fix for this issue.
For Magento Open Source versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier: Update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to sensitive areas of the application to minimize the risk of exploitation.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Commerce
Magento Open Source