First published: Mon Nov 09 2020(Updated: )
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions issue vulnerability in the Inventory module. This vulnerability could be abused by authenticated users to modify inventory stock data without authorization.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/magento/community-edition | >=2.4.0<2.4.1 | 2.4.1 |
composer/magento/community-edition | <=2.3.5-p2 | 2.3.6 |
Magento Magento | <2.3.5 | |
Magento Magento | <2.3.5 | |
Magento Magento | =2.3.5 | |
Magento Magento | =2.3.5 | |
Magento Magento | =2.3.5-p1 | |
Magento Magento | =2.3.5-p1 | |
Magento Magento | =2.4.0 | |
Magento Magento | =2.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-24405.
The severity of CVE-2020-24405 is medium (4.3).
Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by CVE-2020-24405.
CVE-2020-24405 is an incorrect permissions issue vulnerability in the Inventory module of Magento, which allows authenticated users to modify inventory stock data without authorization.
To fix CVE-2020-24405, you should update Magento to version 2.4.1 or 2.3.6, which contain patches for this vulnerability.