Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-49521

Опубликовано: 12 нояб. 2024
Источник: nvd
CVSS3: 7.7
EPSS Низкий

Описание

Adobe Commerce versions 3.2.5 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to a security feature bypass. A low privileged attacker could exploit this vulnerability to send crafted requests from the vulnerable server to internal systems, which could result in the bypassing of security measures such as firewalls. Exploitation of this issue does not require user interaction.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*:*
Версия до 3.2.6 (исключая)
cpe:2.3:a:adobe:magento:*:*:*:*:open_source:*:*:*
Версия до 3.2.6 (исключая)

EPSS

Процентиль: 54%
0.00316
Низкий

7.7 High

CVSS3

Дефекты

CWE-918
CWE-918

Связанные уязвимости

CVSS3: 7.7
github
около 1 года назад

Adobe Commerce versions 3.2.5 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to a security feature bypass. A low privileged attacker could exploit this vulnerability to send crafted requests from the vulnerable server to internal systems, which could result in the bypassing of security measures such as firewalls. Exploitation of this issue does not require user interaction.

CVSS3: 7.7
fstec
около 1 года назад

Уязвимость программных платформ для разработки и управления онлайн магазинами Adobe Commerce и Magento Open Source, связанная с недостаточной проверкой запросов на стороне сервера, позволяющая нарушителю осуществить SSRF-атаку

EPSS

Процентиль: 54%
0.00316
Низкий

7.7 High

CVSS3

Дефекты

CWE-918
CWE-918