CVE-2020-24404: Incorrect permissions in Integrations component could lead to unauthorized deletion of cmsPages via REST API
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability within the Integrations component. This vulnerability could be abused by users with permissions to the Pages resource to delete cms pages via the REST API without authorization.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Magento vulnerability?
The vulnerability ID for this Magento vulnerability is CVE-2020-24404.
What is the severity of CVE-2020-24404?
The severity of CVE-2020-24404 is medium, with a severity value of 2.7.
Which versions of Magento are affected by CVE-2020-24404?
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by CVE-2020-24404.
How can the incorrect permissions vulnerability within the Integrations component be abused?
The incorrect permissions vulnerability within the Integrations component can be abused by users with permissions to the Pages resource to delete CMS pages via the REST API without authorization.
What is the remedy for CVE-2020-24404?
The remedy for CVE-2020-24404 is to update Magento to version 2.4.1 or 2.3.6, depending on the Magento version being used.