Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A low-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction..
Metrics
Affected Vendors & Products
References
History
Wed, 07 Aug 2024 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted request to the server, which could then cause the server to execute arbitrary code. Exploitation of this issue does not require user interaction. | Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A low-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction.. |
MITRE
Status: PUBLISHED
Assigner: adobe
Published: 2024-06-13T09:04:59.166Z
Updated: 2024-08-07T14:51:52.418Z
Reserved: 2024-04-30T19:50:50.903Z
Link: CVE-2024-34111
Vulnrichment
Updated: 2024-08-02T02:43:00.129Z
NVD
Status : Modified
Published: 2024-06-13T09:15:13.537
Modified: 2024-08-07T15:15:54.520
Link: CVE-2024-34111
Redhat
No data.