First published: Thu Oct 01 2020(Updated: )
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect user permissions vulnerability within the Inventory component. This vulnerability could be abused by authenticated users with Inventory and Source permissions to make unauthorized changes to inventory source data via the REST API.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/magento/community-edition | =2.4.0 | 2.4.1 |
composer/magento/community-edition | <2.3.6 | 2.3.6 |
Magento Magento | <2.3.5 | |
Magento Magento | <2.3.5 | |
Magento Magento | =2.3.5 | |
Magento Magento | =2.3.5 | |
Magento Magento | =2.3.5-p1 | |
Magento Magento | =2.3.5-p1 | |
Magento Magento | =2.4.0 | |
Magento Magento | =2.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24403 is a vulnerability in Magento version 2.4.0 and 2.3.5p1 (and earlier) that allows authenticated users with Inventory and Source permissions to make unauthorized changes to inventory source data.
CVE-2020-24403 has a severity rating of 2.7, which is considered medium.
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by CVE-2020-24403.
Authenticated users with Inventory and Source permissions can exploit CVE-2020-24403 to make unauthorized changes to inventory source data.
Yes, a fix is available for CVE-2020-24403. It is recommended to update to the latest version of Magento to mitigate this vulnerability.