Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability in the Integrations component. This vulnerability could be abused by authenticated users with permissions to the Resource Access API to delete customer details via the REST API without authorization.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4218 | Magento incorrect permissions vulnerability in the Integrations component |
Github GHSA |
GHSA-hvf5-4jr9-fghh | Magento incorrect permissions vulnerability in the Integrations component |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: adobe
Published:
Updated: 2024-09-16T19:04:11.706Z
Reserved: 2020-08-19T00:00:00
Link: CVE-2020-24402
No data.
Status : Modified
Published: 2020-11-09T01:15:12.490
Modified: 2024-11-21T05:14:45.167
Link: CVE-2020-24402
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA