PT-2024-6960 · Adobe · Magento Open Source+1

CVE-2024-45124

·

Published

2024-10-08

·

Updated

2024-10-13

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier Magento Open Source versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier
Description The issue is related to insufficient access control in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source, allowing a remote attacker to bypass security restrictions. This could result in a security feature bypass, with a low impact on integrity. Exploitation of this issue does not require user interaction.
Recommendations For Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier: Update to a version that includes the fix for this issue. For Magento Open Source versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier: Update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to sensitive areas of the application to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-08209
BIT-MAGENTO-2024-45124
CVE-2024-45124
GHSA-W3P2-PC3H-69WV

Affected Products

Commerce
Magento Open Source