CVE-2022-24086: Adobe Commerce checkout improper input validation leads to remote code execution
Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution.
Other sources
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/magento/community-editionto a version that resolves this vulnerability.Fixed in 2.4.3-p2 - Upgrade
Upgrade
composer/magento/community-editionto a version that resolves this vulnerability.Fixed in 2.3.7-p3
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-24086.
Which versions of Adobe Commerce and Magento Open Source are affected?
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected.
What is the severity rating of CVE-2022-24086?
CVE-2022-24086 has a severity rating of 9.8 (Critical).
How does the vulnerability manifest?
The vulnerability manifests as an improper input validation vulnerability during the checkout process.
Can this vulnerability be exploited without user interaction?
Yes, exploitation of this issue does not require user interaction.
What is the potential impact of this vulnerability?
Exploitation of this vulnerability could result in arbitrary code execution.
How can I fix CVE-2022-24086?
To fix CVE-2022-24086, update to Adobe Commerce version 2.4.3-p2 (or later) or 2.3.7-p3 (or later).