← Back

CVE-2024-34104

nvd nist
Published: Jun 13, 2024Modified: Nov 21, 2024

JSON object

Loading...
8.2
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Exploitability: 3.9 / Impact: 4.2
Source: psirt@adobe.com (Secondary)

Description

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access, leading to both confidentiality and integrity impact. Exploitation of this issue does not require user interaction.

Affected (71)

3 products
Commerce
Commerce Webhooks
Magento
Configuration A
71 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Version 2.3.7
Version 2.3.7 p1
Version 2.3.7 p2
Version 2.3.7 p3
Version 2.3.7 p4-ext1
Version 2.3.7 p4-ext2
Version 2.3.7 p4-ext3
Version 2.3.7 p4-ext4
Version 2.3.7 p4
Version 2.4.0
Version 2.4.0 ext-1
Version 2.4.0 ext-2
Version 2.4.0 ext-3
Version 2.4.0 ext-4
Version 2.4.1
Version 2.4.1 ext-1
Version 2.4.1 ext-2
Version 2.4.1 ext-3
Version 2.4.1 ext-4
Version 2.4.2
Version 2.4.2 ext-1
Version 2.4.2 ext-2
Version 2.4.2 ext-3
Version 2.4.2 ext-4
Version 2.4.3
Version 2.4.3 ext-1
Version 2.4.3 ext-2
Version 2.4.3 ext-3
Version 2.4.3 ext-4
Version 2.4.4
Version 2.4.4 p1
Version 2.4.4 p2
Version 2.4.4 p3
Version 2.4.4 p4
Version 2.4.4 p5
Version 2.4.4 p6
Version 2.4.5
Version 2.4.5 p1
Version 2.4.5 p2
Version 2.4.5 p3
Version 2.4.5 p4
Version 2.4.5 p5
Version 2.4.6
Version 2.4.6 p1
Version 2.4.6 p2
Version 2.4.6 p3
From 1.2.0 to 1.4.0
Adobe
Version 2.4.4
Version 2.4.4 p1
Version 2.4.4 p2
Version 2.4.4 p3
Version 2.4.4 p4
Version 2.4.4 p5
Version 2.4.4 p6
Version 2.4.4 p7
Version 2.4.4 p8
Version 2.4.5
Version 2.4.5 p1
Version 2.4.5 p2
Version 2.4.5 p3
Version 2.4.5 p4
Version 2.4.5 p5
Version 2.4.5 p6
Version 2.4.5 p7
Version 2.4.6
Version 2.4.6 p1
Version 2.4.6 p2
Version 2.4.6 p3
Version 2.4.6 p4
Version 2.4.6 p5
Version 2.4.7 b1

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.