CVE-2024-34108
Large attack surface through legit webhook usage in Adobe Commerce
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, but admin privileges are required
Las versiones 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 y anteriores de Adobe Commerce se ven afectadas por una vulnerabilidad de validación de entrada incorrecta que podría provocar la ejecución de código arbitrario en el contexto del usuario actual. La explotación de este problema no requiere la interacción del usuario, pero se requieren privilegios de administrador
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, but admin privileges are required and scope is changed.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-04-30 CVE Reserved
- 2024-06-13 CVE Published
- 2024-07-15 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://helpx.adobe.com/security/products/magento/apsb24-40.html | 2024-07-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.3.7 Search vendor "Adobe" for product "Commerce" and version "2.3.7" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.3.7 Search vendor "Adobe" for product "Commerce" and version "2.3.7" | p1 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.3.7 Search vendor "Adobe" for product "Commerce" and version "2.3.7" | p2 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.3.7 Search vendor "Adobe" for product "Commerce" and version "2.3.7" | p3 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.3.7 Search vendor "Adobe" for product "Commerce" and version "2.3.7" | p4 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.3.7 Search vendor "Adobe" for product "Commerce" and version "2.3.7" | p4-ext1 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.3.7 Search vendor "Adobe" for product "Commerce" and version "2.3.7" | p4-ext2 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.3.7 Search vendor "Adobe" for product "Commerce" and version "2.3.7" | p4-ext3 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.3.7 Search vendor "Adobe" for product "Commerce" and version "2.3.7" | p4-ext4 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.0 Search vendor "Adobe" for product "Commerce" and version "2.4.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.0 Search vendor "Adobe" for product "Commerce" and version "2.4.0" | ext-1 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.0 Search vendor "Adobe" for product "Commerce" and version "2.4.0" | ext-2 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.0 Search vendor "Adobe" for product "Commerce" and version "2.4.0" | ext-3 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.0 Search vendor "Adobe" for product "Commerce" and version "2.4.0" | ext-4 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.1 Search vendor "Adobe" for product "Commerce" and version "2.4.1" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.1 Search vendor "Adobe" for product "Commerce" and version "2.4.1" | ext-1 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.1 Search vendor "Adobe" for product "Commerce" and version "2.4.1" | ext-2 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.1 Search vendor "Adobe" for product "Commerce" and version "2.4.1" | ext-3 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.1 Search vendor "Adobe" for product "Commerce" and version "2.4.1" | ext-4 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.2 Search vendor "Adobe" for product "Commerce" and version "2.4.2" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.2 Search vendor "Adobe" for product "Commerce" and version "2.4.2" | ext-1 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.2 Search vendor "Adobe" for product "Commerce" and version "2.4.2" | ext-2 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.2 Search vendor "Adobe" for product "Commerce" and version "2.4.2" | ext-3 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.2 Search vendor "Adobe" for product "Commerce" and version "2.4.2" | ext-4 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.3 Search vendor "Adobe" for product "Commerce" and version "2.4.3" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.3 Search vendor "Adobe" for product "Commerce" and version "2.4.3" | ext-1 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.3 Search vendor "Adobe" for product "Commerce" and version "2.4.3" | ext-2 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.3 Search vendor "Adobe" for product "Commerce" and version "2.4.3" | ext-3 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.3 Search vendor "Adobe" for product "Commerce" and version "2.4.3" | ext-4 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.4 Search vendor "Adobe" for product "Commerce" and version "2.4.4" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.4 Search vendor "Adobe" for product "Commerce" and version "2.4.4" | p1 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.4 Search vendor "Adobe" for product "Commerce" and version "2.4.4" | p2 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.4 Search vendor "Adobe" for product "Commerce" and version "2.4.4" | p3 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.4 Search vendor "Adobe" for product "Commerce" and version "2.4.4" | p4 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.4 Search vendor "Adobe" for product "Commerce" and version "2.4.4" | p5 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.4 Search vendor "Adobe" for product "Commerce" and version "2.4.4" | p6 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.5 Search vendor "Adobe" for product "Commerce" and version "2.4.5" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.5 Search vendor "Adobe" for product "Commerce" and version "2.4.5" | p1 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.5 Search vendor "Adobe" for product "Commerce" and version "2.4.5" | p2 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.5 Search vendor "Adobe" for product "Commerce" and version "2.4.5" | p3 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.5 Search vendor "Adobe" for product "Commerce" and version "2.4.5" | p4 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.5 Search vendor "Adobe" for product "Commerce" and version "2.4.5" | p5 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.6 Search vendor "Adobe" for product "Commerce" and version "2.4.6" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.6 Search vendor "Adobe" for product "Commerce" and version "2.4.6" | p1 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.6 Search vendor "Adobe" for product "Commerce" and version "2.4.6" | p2 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.6 Search vendor "Adobe" for product "Commerce" and version "2.4.6" | p3 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Webhooks Search vendor "Adobe" for product "Commerce Webhooks" | >= 1.2.0 <= 1.4.0 Search vendor "Adobe" for product "Commerce Webhooks" and version " >= 1.2.0 <= 1.4.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Magento Search vendor "Adobe" for product "Magento" | 2.4.4 Search vendor "Adobe" for product "Magento" and version "2.4.4" | open_source |
Affected
| ||||||
Adobe Search vendor "Adobe" | Magento Search vendor "Adobe" for product "Magento" | 2.4.4 Search vendor "Adobe" for product "Magento" and version "2.4.4" | p1, open_source |
Affected
| ||||||
Adobe Search vendor "Adobe" | Magento Search vendor "Adobe" for product "Magento" | 2.4.4 Search vendor "Adobe" for product "Magento" and version "2.4.4" | p2, open_source |
Affected
| ||||||
Adobe Search vendor "Adobe" | Magento Search vendor "Adobe" for product "Magento" | 2.4.4 Search vendor "Adobe" for product "Magento" and version "2.4.4" | p3, open_source |
Affected
| ||||||
Adobe Search vendor "Adobe" | Magento Search vendor "Adobe" for product "Magento" | 2.4.4 Search vendor "Adobe" for product "Magento" and version "2.4.4" | p4, open_source |
Affected
| ||||||
Adobe Search vendor "Adobe" | Magento Search vendor "Adobe" for product "Magento" | 2.4.4 Search vendor "Adobe" for product "Magento" and version "2.4.4" | p5, open_source |
Affected
| ||||||
Adobe Search vendor "Adobe" | Magento Search vendor "Adobe" for product "Magento" | 2.4.4 Search vendor "Adobe" for product "Magento" and version "2.4.4" | p6, open_source |
Affected
| ||||||
Adobe Search vendor "Adobe" | Magento Search vendor "Adobe" for product "Magento" | 2.4.4 Search vendor "Adobe" for product "Magento" and version "2.4.4" | p7, open_source |
Affected
| ||||||
Adobe Search vendor "Adobe" | Magento Search vendor "Adobe" for product "Magento" | 2.4.4 Search vendor "Adobe" for product "Magento" and version "2.4.4" | p8, open_source |
Affected
| ||||||
Adobe Search vendor "Adobe" | Magento Search vendor "Adobe" for product "Magento" | 2.4.5 Search vendor "Adobe" for product "Magento" and version "2.4.5" | open_source |
Affected
| ||||||
Adobe Search vendor "Adobe" | Magento Search vendor "Adobe" for product "Magento" | 2.4.5 Search vendor "Adobe" for product "Magento" and version "2.4.5" | p1, open_source |
Affected
| ||||||
Adobe Search vendor "Adobe" | Magento Search vendor "Adobe" for product "Magento" | 2.4.5 Search vendor "Adobe" for product "Magento" and version "2.4.5" | p2, open_source |
Affected
| ||||||
Adobe Search vendor "Adobe" | Magento Search vendor "Adobe" for product "Magento" | 2.4.5 Search vendor "Adobe" for product "Magento" and version "2.4.5" | p3, open_source |
Affected
| ||||||
Adobe Search vendor "Adobe" | Magento Search vendor "Adobe" for product "Magento" | 2.4.5 Search vendor "Adobe" for product "Magento" and version "2.4.5" | p4, open_source |
Affected
| ||||||
Adobe Search vendor "Adobe" | Magento Search vendor "Adobe" for product "Magento" | 2.4.5 Search vendor "Adobe" for product "Magento" and version "2.4.5" | p5, open_source |
Affected
| ||||||
Adobe Search vendor "Adobe" | Magento Search vendor "Adobe" for product "Magento" | 2.4.5 Search vendor "Adobe" for product "Magento" and version "2.4.5" | p6, open_source |
Affected
| ||||||
Adobe Search vendor "Adobe" | Magento Search vendor "Adobe" for product "Magento" | 2.4.5 Search vendor "Adobe" for product "Magento" and version "2.4.5" | p7, open_source |
Affected
| ||||||
Adobe Search vendor "Adobe" | Magento Search vendor "Adobe" for product "Magento" | 2.4.6 Search vendor "Adobe" for product "Magento" and version "2.4.6" | open_source |
Affected
| ||||||
Adobe Search vendor "Adobe" | Magento Search vendor "Adobe" for product "Magento" | 2.4.6 Search vendor "Adobe" for product "Magento" and version "2.4.6" | p1, open_source |
Affected
| ||||||
Adobe Search vendor "Adobe" | Magento Search vendor "Adobe" for product "Magento" | 2.4.6 Search vendor "Adobe" for product "Magento" and version "2.4.6" | p2, open_source |
Affected
| ||||||
Adobe Search vendor "Adobe" | Magento Search vendor "Adobe" for product "Magento" | 2.4.6 Search vendor "Adobe" for product "Magento" and version "2.4.6" | p3, open_source |
Affected
| ||||||
Adobe Search vendor "Adobe" | Magento Search vendor "Adobe" for product "Magento" | 2.4.6 Search vendor "Adobe" for product "Magento" and version "2.4.6" | p4, open_source |
Affected
| ||||||
Adobe Search vendor "Adobe" | Magento Search vendor "Adobe" for product "Magento" | 2.4.6 Search vendor "Adobe" for product "Magento" and version "2.4.6" | p5, open_source |
Affected
| ||||||
Adobe Search vendor "Adobe" | Magento Search vendor "Adobe" for product "Magento" | 2.4.7 Search vendor "Adobe" for product "Magento" and version "2.4.7" | b1, open_source |
Affected
|