Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A low-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction..
Advisories
Source ID Title
EUVD EUVD EUVD-2024-2094 Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A low-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction..
Github GHSA Github GHSA GHSA-jmqp-r3gg-6jh3 Magento Open Source Server-Side Request Forgery (SSRF) vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 07 Aug 2024 15:00:00 +0000

Type Values Removed Values Added
Description Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted request to the server, which could then cause the server to execute arbitrary code. Exploitation of this issue does not require user interaction. Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A low-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction..

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2024-08-07T14:51:52.418Z

Reserved: 2024-04-30T19:50:50.903Z

Link: CVE-2024-34111

cve-icon Vulnrichment

Updated: 2024-08-02T02:43:00.129Z

cve-icon NVD

Status : Modified

Published: 2024-06-13T09:15:13.537

Modified: 2024-11-21T09:18:07.443

Link: CVE-2024-34111

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.