PT-2024-6966 · Adobe · Magento Open Source+1
Published
2024-10-08
·
Updated
2024-10-15
·
CVE-2024-45117
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier
Magento Open Source versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier
Description
The issue is related to insufficient input validation in Adobe Commerce and Magento Open Source, allowing a remote attacker to disclose protected information. An admin attacker could exploit this vulnerability to read files from the system outside of the intended directories via PHP filter chain, potentially having a low-availability impact on the service. Exploitation of this issue does not require user interaction.
Recommendations
For Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier, upgrade to a newer version to mitigate the risk.
For Magento Open Source versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier, upgrade to a newer version to mitigate the risk.
As a temporary workaround, consider restricting access to the PHP filter chain to minimize the risk of exploitation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Commerce
Magento Open Source