Описание
Magento Improper Authorization vulnerability
Magento versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.
Пакеты
magento/community-edition
< 2.4.4-p13
2.4.4-p13
magento/community-edition
= 2.4.4
Отсутствует
magento/community-edition
= 2.4.5
Отсутствует
magento/community-edition
= 2.4.6
Отсутствует
magento/community-edition
>= 2.4.5-p1, < 2.4.5-p12
2.4.5-p12
magento/community-edition
>= 2.4.6-p1, < 2.4.6-p10
2.4.6-p10
magento/community-edition
>= 2.4.7-p1, < 2.4.7-p5
2.4.7-p5
magento/community-edition
= 2.4.7
Отсутствует
magento/community-edition
>= 2.4.8-beta1, < 2.4.8
2.4.8
Связанные уязвимости
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.
Уязвимость программных платформ для разработки и управления онлайн магазинами Magento Open Source, Adobe Commerce и Adobe Commerce B2B, связанная с недостатками процедуры авторизации, позволяющая нарушителю повысить свои привилегии