Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access, leading to both confidentiality and integrity impact. Exploitation of this issue does not require user interaction.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-2198 Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access, leading to both confidentiality and integrity impact. Exploitation of this issue does not require user interaction.
Github GHSA Github GHSA GHSA-wwj3-573j-rvvm Magento Open Source Improper Authorization vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 17 Sep 2024 11:15:00 +0000

Type Values Removed Values Added
Title Existing orders can be overwritten by anothers user cart via PUT to `/rest/default/V1/carts/mine` Adobe Commerce | Improper Authorization (CWE-285)

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2024-09-17T11:08:38.931Z

Reserved: 2024-04-30T19:50:50.901Z

Link: CVE-2024-34104

cve-icon Vulnrichment

Updated: 2024-08-02T02:43:00.447Z

cve-icon NVD

Status : Modified

Published: 2024-06-13T09:15:11.017

Modified: 2024-11-21T09:18:06.377

Link: CVE-2024-34104

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.