PT-2024-6966 · Adobe · Magento Open Source+1

Published

2024-10-08

·

Updated

2024-10-15

·

CVE-2024-45117

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier Magento Open Source versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier
Description The issue is related to insufficient input validation in Adobe Commerce and Magento Open Source, allowing a remote attacker to disclose protected information. An admin attacker could exploit this vulnerability to read files from the system outside of the intended directories via PHP filter chain, potentially having a low-availability impact on the service. Exploitation of this issue does not require user interaction.
Recommendations For Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier, upgrade to a newer version to mitigate the risk. For Magento Open Source versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier, upgrade to a newer version to mitigate the risk. As a temporary workaround, consider restricting access to the PHP filter chain to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-08215
CVE-2024-45117
GHSA-3FR3-GCQH-3M2G

Affected Products

Commerce
Magento Open Source