← Back

CVE-2024-34102

Published: Jun 13, 2024Modified: Oct 23, 2025CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: psirt@adobe.com (Secondary)

Description

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.

Affected (59)

3 products
Commerce
Commerce Webhooks
Magento
Configuration A
59 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Version 2.4.2
Version 2.4.2 ext-1
Version 2.4.2 ext-2
Version 2.4.2 ext-3
Version 2.4.2 ext-4
Version 2.4.2 ext-7
Version 2.4.3
Version 2.4.3 ext-1
Version 2.4.3 ext-2
Version 2.4.3 ext-3
Version 2.4.3 ext-4
Version 2.4.3 ext-7
Version 2.4.4
Version 2.4.4 p1
Version 2.4.4 p2
Version 2.4.4 p3
Version 2.4.4 p4
Version 2.4.4 p5
Version 2.4.4 p6
Version 2.4.4 p8
Version 2.4.5
Version 2.4.5 p1
Version 2.4.5 p2
Version 2.4.5 p3
Version 2.4.5 p4
Version 2.4.5 p5
Version 2.4.5 p7
Version 2.4.6
Version 2.4.6 p1
Version 2.4.6 p2
Version 2.4.6 p3
Version 2.4.6 p5
Version 2.4.7
From 1.2.0 to 1.5.0
Adobe
Version 2.4.4
Version 2.4.4 p1
Version 2.4.4 p2
Version 2.4.4 p3
Version 2.4.4 p4
Version 2.4.4 p5
Version 2.4.4 p6
Version 2.4.4 p7
Version 2.4.4 p8
Version 2.4.5
Version 2.4.5 p1
Version 2.4.5 p2
Version 2.4.5 p3
Version 2.4.5 p4
Version 2.4.5 p5
Version 2.4.5 p6
Version 2.4.5 p7
Version 2.4.6
Version 2.4.6 p1
Version 2.4.6 p2
Version 2.4.6 p3
Version 2.4.6 p4
Version 2.4.6 p5
Version 2.4.7
Version 2.4.7 b1

References (5)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitTechnical DescriptionThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.