CVE-2024-34102

CRITICAL(9.8)KEVWahrscheinlich ausgenutzt

Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability

Beschreibung

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.

KEV-Informationen

Hersteller
Adobe
Produkt
Commerce and Magento Open Source
Hinzugefügt am
17. Juli 2024
Fälligkeitsdatum
7. August 2024
Erforderliche Maßnahme
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS-Score

Vektorstring
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HIm Rechner öffnen
Angriffsvektor
NETWORK
Angriffskomplexität
LOW
Erforderliche Privilegien
NONE
Benutzerinteraktion
NONE
Scope
UNCHANGED
Vertraulichkeitsauswirkung
HIGH
Integritätsauswirkung
HIGH
Verfügbarkeitsauswirkung
HIGH
Ausnutzbarkeitsscore
3.9
Auswirkungsscore
5.9

CWEs

Betroffene Produkte

HerstellerProduktVersion
adobecommerce2.4.2; 2.4.3; 2.4.4; 2.4.5; 2.4.6; 2.4.7
adobecommerce webhooks>= 1.2.0, < 1.5.0
adobemagento2.4.4; 2.4.5; 2.4.6; 2.4.7

Referenzen

CVSS-Score

9.8
CRITICAL(9.8)

EPSS-Score

EPSS-Score99.99%
EPSS-Perzentil100.0%

Daten

Veröffentlicht13. Juni 2024
Zuletzt geändert17. Juni 2026
StatusAnalyzed
CVSS-Versionv3.1

Hilfe beim Schwachstellenmanagement?

Unsere Sicherheitsexperten helfen Ihnen bei der Priorisierung und Behebung von Schwachstellen.