Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability in the Integrations component. This vulnerability could be abused by authenticated users with permissions to the Resource Access API to delete customer details via the REST API without authorization.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: adobe
Published: 2020-11-09T00:39:15.182126Z
Updated: 2024-09-16T19:04:11.706Z
Reserved: 2020-08-19T00:00:00
Link: CVE-2020-24402
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-11-09T01:15:12.490
Modified: 2024-11-21T05:14:45.167
Link: CVE-2020-24402
Redhat
No data.