When in maintenance mode, Magento version 2.4.0 and 2.3.4 (and earlier) are affected by an information disclosure vulnerability that could expose the installation path during build deployments. This information could be helpful to attackers if they are able to identify other exploitable vulnerabilities in the environment.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published: 2020-11-09T00:39:49.001589Z

Updated: 2024-09-17T01:12:06.334Z

Reserved: 2020-08-19T00:00:00

Link: CVE-2020-24406

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-11-09T01:15:12.880

Modified: 2020-11-12T18:01:05.987

Link: CVE-2020-24406

cve-icon Redhat

No data.