QID 996658

Date Published: 2024-01-15

QID 996658: PHP (Composer) Security Update for magento/community-edition (GHSA-r7mm-grf3-5fjv)

Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to access other user's data. Exploitation of this issue does not require user interaction.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-r7mm-grf3-5fjv for updates and patch information.
    Vendor References

    CVEs related to QID 996658

    Software Advisories
    Advisory ID Software Component Link
    GHSA-r7mm-grf3-5fjv magento/community-edition URL Logo github.com/advisories/GHSA-r7mm-grf3-5fjv