CVE-2020-24401: Incorrect permissions following the deletion of a user role or deactivation of a user
Published Nov 9, 2020
·Updated
Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect authorization vulnerability. A user can still access resources provisioned under their old role after an administrator removes the role or disables the user's account.
Affected Software
10 affected componentsFixes available
composer/magento/project-community-edition<=2.0.2
composer/magento/community-edition<=2.4.0
2.4.1
Magento Magento<2.3.5
Magento Magento<2.3.5
Magento Magento=2.3.5
Magento Magento=2.3.5
Magento Magento=2.3.5-p1
Magento Magento=2.3.5-p1
Magento Magento=2.4.0
Magento Magento=2.4.0
Event History
Nov 9, 2020
CVE Published
via MITRE·12:39 AM
Data Sourced
via MITRE·12:39 AM
DescriptionSeverityWeakness
May 24, 2022
Advisory Published
via GitHub·05:33 PM
Frequently Asked Questions
1
What is the vulnerability ID of this Magento vulnerability?
The vulnerability ID of this Magento vulnerability is CVE-2020-24401.
2
What is the title of this Magento vulnerability?
The title of this Magento vulnerability is 'Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect authorization vulnerability.'
3
What is the severity of CVE-2020-24401?
The severity of CVE-2020-24401 is medium, with a severity value of 6.5.
4
Which Magento versions are affected by CVE-2020-24401?
Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by CVE-2020-24401.
5
How can I fix the incorrect authorization vulnerability in Magento?
To fix the incorrect authorization vulnerability in Magento, update to version 2.4.1 or a later version.