CVE-2020-24403: Incorrect permissions could lead to unauthorized modification of inventory source data via REST API
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect user permissions vulnerability within the Inventory component. This vulnerability could be abused by authenticated users with Inventory and Source permissions to make unauthorized changes to inventory source data via the REST API.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-24403?
CVE-2020-24403 is a vulnerability in Magento version 2.4.0 and 2.3.5p1 (and earlier) that allows authenticated users with Inventory and Source permissions to make unauthorized changes to inventory source data.
How severe is CVE-2020-24403?
CVE-2020-24403 has a severity rating of 2.7, which is considered medium.
Which versions of Magento are affected by CVE-2020-24403?
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by CVE-2020-24403.
How can the vulnerability CVE-2020-24403 be exploited?
Authenticated users with Inventory and Source permissions can exploit CVE-2020-24403 to make unauthorized changes to inventory source data.
Is there a fix available for CVE-2020-24403?
Yes, a fix is available for CVE-2020-24403. It is recommended to update to the latest version of Magento to mitigate this vulnerability.