CVE-2022-24086
CRITICAL(9.8)KEVWahrscheinlich ausgenutzt
Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability
Beschreibung
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.
KEV-Informationen
CVSS-Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HIm Rechner öffnenBetroffene Produkte
| Hersteller | Produkt | Version |
|---|---|---|
| adobe | commerce | < 2.3.0; >= 2.3.3, <= 2.3.6; >= 2.4.0, <= 2.4.2; 2.3.7; 2.4.3 |
| adobe | magento | < 2.3.0; > 2.3.3, <= 2.3.6; >= 2.4.0, <= 2.4.2; 2.3.7; 2.4.3 |
Referenzen
- https://helpx.adobe.com/security/products/magento/apsb22-12.html(Patch, Release Notes, Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-24086(Third Party Advisory, US Government Resource)
Hilfe beim Schwachstellenmanagement?
Unsere Sicherheitsexperten helfen Ihnen bei der Priorisierung und Behebung von Schwachstellen.