PT-2024-6972 · Adobe · Magento Open Source+1

Published

2024-10-08

·

Updated

2024-10-14

·

CVE-2024-45131

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier Magento Open Source versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier
Description The issue is related to a lack of proper authorization in the mechanism of Adobe Commerce and Magento Open Source platforms. This could allow a remote attacker to bypass security restrictions. A low-privileged attacker could leverage this issue to bypass security measures, having a low impact on confidentiality and integrity. Exploitation of this issue does not require user interaction.
Recommendations For Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier, update to a version that includes the fix for this issue. For Magento Open Source versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to sensitive areas of the platform to minimize the risk of exploitation.

Fix

Incorrect Authorization

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-08221
BIT-MAGENTO-2024-45131
CVE-2024-45131
GHSA-XC5P-773W-M3PM

Affected Products

Commerce
Magento Open Source