Описание
Magento Open Source has Improper Access Control vulnerability
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to leak minor information of another user's account details. Exploitation of this issue does not require user interaction.
Пакеты
magento/community-edition
>= 2.4.3-p1, < 2.4.3-p3
2.4.3-p3
magento/community-edition
>= 2.3.7-p1, < 2.3.7-p4
2.3.7-p4
magento/project-community-edition
<= 2.0.2
Отсутствует
magento/community-edition
= 2.3.7
Отсутствует
magento/community-edition
= 2.4.4
Отсутствует
magento/community-edition
= 2.4.3
Отсутствует
Связанные уязвимости
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to leak minor information of another user's account detials. Exploitation of this issue does not require user interaction.
Уязвимость программных платформ для разработки и управления онлайн магазинами Magento Open Source и Adobe Commerce, связанная с недостатками механизма авторизации, позволяющая нарушителю раскрыть информацию о данных учетной записи произвольных пользователей