QID 996647

Date Published: 2024-01-15

QID 996647: PHP (Composer) Security Update for magento/community-edition (GHSA-7gh6-f4jh-3crq)

Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Violation of Secure Design Principles vulnerability in RMA PDF filename formats. Successful exploitation could allow an attacker to get unauthorized access to restricted resources.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 4.2 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Refer to Github security advisory GHSA-7gh6-f4jh-3crq for updates and patch information.
    Vendor References

    CVEs related to QID 996647

    Software Advisories
    Advisory ID Software Component Link
    GHSA-7gh6-f4jh-3crq magento/community-edition URL Logo github.com/advisories/GHSA-7gh6-f4jh-3crq