CVE-2024-34107
MEDIUM5.3EPSS 0.73%Magento Open Source Improper Access Control vulnerability
Published: 6/13/2024Modified: 8/7/2024
Description
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.
Affected packages (2)
- Bitnami/magento>= 2.4.7-alpha0, < 2.4.7-p1, >= 2.4.6-alpha0, < 2.4.6-p6, >= 2.4.5-alpha0, < 2.4.5-p8, >= 2.4.4-alpha0, < 2.4.4-p9
- Packagist/magento/community-edition
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
References (7)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2024-34107
- PATCHhttps://github.com/magento/magento2
- WEBhttps://github.com/magento/magento2/commit/30877fce83b793f71421c47347885cf076e81799
- WEBhttps://github.com/magento/magento2/commit/a3c6d6e5e95e63031e4df26cfcf76feace7549c2
- WEBhttps://github.com/magento/magento2/commit/c5c538810b87449886f4669cb8abbe8e5593c83c
- WEBhttps://github.com/magento/magento2/commit/d10435b11ada4e502dca7539f8fd31d059d3c482
- WEBhttps://helpx.adobe.com/security/products/magento/apsb24-40.html