QID 996662
Date Published: 2024-01-15
QID 996662: PHP (Composer) Security Update for magento/community-edition (GHSA-39rw-4m66-82gf)
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect user permissions vulnerability within the Inventory component. This vulnerability could be abused by authenticated users with Inventory and Source permissions to make unauthorized changes to inventory source data via the REST API.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-39rw-4m66-82gf for updates and patch information.
Vendor References
- GHSA-39rw-4m66-82gf -
github.com/advisories/GHSA-39rw-4m66-82gf
CVEs related to QID 996662
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-39rw-4m66-82gf | magento/community-edition |
|