Описание
Magento Improper Access Control leads to Security feature bypass
Magento versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.
Пакеты
magento/project-community-edition
<= 2.0.2
Отсутствует
magento/community-edition
>= 2.4.7-beta1, < 2.4.7-p5
2.4.7-p5
magento/community-edition
>= 2.4.6-p1, < 2.4.6-p10
2.4.6-p10
magento/community-edition
>= 2.4.5-p1, < 2.4.5-p12
2.4.5-p12
magento/community-edition
< 2.4.4-p13
2.4.4-p13
magento/community-edition
>= 2.4.8-beta1, < 2.4.8-beta2
2.4.8-beta2
magento/community-edition
= 2.4.5
Отсутствует
magento/community-edition
= 2.4.4
Отсутствует
magento/community-edition
= 2.4.6
Отсутствует
magento/community-edition
= 2.4.7
Отсутствует
Связанные уязвимости
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.
Уязвимость программных платформ для разработки и управления онлайн магазинами Magento Open Source, Adobe Commerce и Adobe Commerce B2B, связанная с недостатками разграничения доступа, позволяющая нарушителю обойти существующие ограничения безопасности