Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access, leading to both confidentiality and integrity impact. Exploitation of this issue does not require user interaction.
History

Tue, 17 Sep 2024 11:15:00 +0000

Type Values Removed Values Added
Title Existing orders can be overwritten by anothers user cart via PUT to `/rest/default/V1/carts/mine` Adobe Commerce | Improper Authorization (CWE-285)

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published: 2024-06-13T09:04:56.852Z

Updated: 2024-09-17T11:08:38.931Z

Reserved: 2024-04-30T19:50:50.901Z

Link: CVE-2024-34104

cve-icon Vulnrichment

Updated: 2024-08-02T02:43:00.447Z

cve-icon NVD

Status : Modified

Published: 2024-06-13T09:15:11.017

Modified: 2024-11-21T09:18:06.377

Link: CVE-2024-34104

cve-icon Redhat

No data.