PT-2024-6961 · Adobe · Magento Open Source+1
Published
2024-10-08
·
Updated
2024-10-14
·
CVE-2024-45128
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Adobe Commerce versions 2.4.7-p2 through 2.4.4-p10 and earlier
Magento Open Source versions 2.4.7-p2 through 2.4.4-p10 and earlier
Description
The issue is related to an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on integrity and availability. Exploitation of this issue does not require user interaction.
Recommendations
For Adobe Commerce versions 2.4.7-p2 through 2.4.4-p10 and earlier, update to a version that fixes the Improper Authorization vulnerability.
For Magento Open Source versions 2.4.7-p2 through 2.4.4-p10 and earlier, update to a version that fixes the Improper Authorization vulnerability.
As a temporary workaround, consider restricting access to security-sensitive features until a patch is available.
Avoid relying solely on security measures that can be bypassed by exploiting this vulnerability, and consider implementing additional security controls to minimize the risk of exploitation.
Fix
Incorrect Authorization
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Commerce
Magento Open Source