First published: Thu Oct 15 2020(Updated: )
When in maintenance mode, Magento version 2.4.0 and 2.3.4 (and earlier) are affected by an information disclosure vulnerability that could expose the installation path during build deployments. This information could be helpful to attackers if they are able to identify other exploitable vulnerabilities in the environment.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/magento/community-edition | =2.4.0 | 2.4.1 |
composer/magento/community-edition | <2.3.6 | 2.3.6 |
Magento Magento | <=2.3.4 | |
Magento Magento | <=2.3.4 | |
Magento Magento | =2.4.0 | |
Magento Magento | =2.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-24406 is medium (3.7).
Magento version 2.4.0 and 2.3.4 (and earlier) are affected by CVE-2020-24406.
CVE-2020-24406 is an information disclosure vulnerability in Magento when in maintenance mode.
CVE-2020-24406 can expose the installation path during build deployments in Magento.
If an attacker identifies other exploitable vulnerabilities, knowledge of the installation path obtained through CVE-2020-24406 could be helpful.