PT-2024-6961 · Adobe · Magento Open Source+1

Published

2024-10-08

·

Updated

2024-10-14

·

CVE-2024-45128

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Adobe Commerce versions 2.4.7-p2 through 2.4.4-p10 and earlier Magento Open Source versions 2.4.7-p2 through 2.4.4-p10 and earlier
Description The issue is related to an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on integrity and availability. Exploitation of this issue does not require user interaction.
Recommendations For Adobe Commerce versions 2.4.7-p2 through 2.4.4-p10 and earlier, update to a version that fixes the Improper Authorization vulnerability. For Magento Open Source versions 2.4.7-p2 through 2.4.4-p10 and earlier, update to a version that fixes the Improper Authorization vulnerability. As a temporary workaround, consider restricting access to security-sensitive features until a patch is available. Avoid relying solely on security measures that can be bypassed by exploiting this vulnerability, and consider implementing additional security controls to minimize the risk of exploitation.

Fix

Incorrect Authorization

Improper Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-08210
BIT-MAGENTO-2024-45128
CVE-2024-45128
GHSA-QPP7-742Q-58J3

Affected Products

Commerce
Magento Open Source