CVE-2020-24405: Incorrect permissions in Inventory module could lead to unauthorized modification of inventory stock data
Published Nov 9, 2020
·Updated
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions issue vulnerability in the Inventory module. This vulnerability could be abused by authenticated users to modify inventory stock data without authorization.
Affected Software
10 affected componentsFixes available
composer/magento/community-edition>=2.4.0<2.4.1
2.4.1
composer/magento/community-edition<=2.3.5-p2
2.3.6
Magento Magento<2.3.5
Magento Magento<2.3.5
Magento Magento=2.3.5
Magento Magento=2.3.5
Magento Magento=2.3.5-p1
Magento Magento=2.3.5-p1
Magento Magento=2.4.0
Magento Magento=2.4.0
Event History
Nov 9, 2020
CVE Published
via MITRE·12:39 AM
Data Sourced
via MITRE·12:39 AM
DescriptionSeverityWeakness
May 24, 2022
Advisory Published
via GitHub·05:33 PM
Frequently Asked Questions
1
What is the vulnerability ID of this Magento vulnerability?
The vulnerability ID is CVE-2020-24405.
2
What is the severity of CVE-2020-24405?
The severity of CVE-2020-24405 is medium (4.3).
3
Which versions of Magento are affected by CVE-2020-24405?
Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by CVE-2020-24405.
4
What is the description of CVE-2020-24405?
CVE-2020-24405 is an incorrect permissions issue vulnerability in the Inventory module of Magento, which allows authenticated users to modify inventory stock data without authorization.
5
How can I fix CVE-2020-24405?
To fix CVE-2020-24405, you should update Magento to version 2.4.1 or 2.3.6, which contain patches for this vulnerability.