Description
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access, leading to both confidentiality and integrity impact. Exploitation of this issue does not require user interaction.
Published: 2024-06-13
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-2198 Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access, leading to both confidentiality and integrity impact. Exploitation of this issue does not require user interaction.
Github GHSA Github GHSA GHSA-wwj3-573j-rvvm Magento Open Source Improper Authorization vulnerability
History

Tue, 17 Sep 2024 11:15:00 +0000

Type Values Removed Values Added
Title Existing orders can be overwritten by anothers user cart via PUT to `/rest/default/V1/carts/mine` Adobe Commerce | Improper Authorization (CWE-285)

Subscriptions

Adobe Commerce Commerce Webhooks Magento
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2024-09-17T11:08:38.931Z

Reserved: 2024-04-30T19:50:50.901Z

Link: CVE-2024-34104

cve-icon Vulnrichment

Updated: 2024-08-02T02:43:00.447Z

cve-icon NVD

Status : Modified

Published: 2024-06-13T09:15:11.017

Modified: 2024-11-21T09:18:06.377

Link: CVE-2024-34104

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses