First published: Tue Aug 16 2022(Updated: )
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to access other user's data. Exploitation of this issue does not require user interaction.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/magento/community-edition | >=2.4.0<2.4.3-p3 | 2.4.3-p3 |
composer/magento/community-edition | >=2.4.4<2.4.5 | 2.4.5 |
composer/magento/community-edition | >=2.3.0<2.3.7-p4 | 2.3.7-p4 |
Adobe Commerce | >=2.3.0<2.3.7 | |
Adobe Commerce | >=2.4.0<2.4.3 | |
Adobe Commerce | =2.3.7 | |
Adobe Commerce | =2.3.7-p1 | |
Adobe Commerce | =2.3.7-p2 | |
Adobe Commerce | =2.3.7-p3 | |
Adobe Commerce | =2.4.3 | |
Adobe Commerce | =2.4.3-p1 | |
Adobe Commerce | =2.4.3-p2 | |
Adobe Commerce | =2.4.4 | |
Magento Magento | >=2.3.0<2.3.7 | |
Magento Magento | >=2.4.0<2.4.3 | |
Magento Magento | =2.3.7 | |
Magento Magento | =2.3.7-p1 | |
Magento Magento | =2.3.7-p2 | |
Magento Magento | =2.3.7-p3 | |
Magento Magento | =2.4.3 | |
Magento Magento | =2.4.3-p1 | |
Magento Magento | =2.4.3-p2 | |
Magento Magento | =2.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-34256.
The severity of CVE-2022-34256 is critical with a CVSS score of 9.8.
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier), and 2.4.4 (and earlier) are affected by CVE-2022-34256.
CVE-2022-34256 allows attackers to escalate privileges and access other user's data.
You can find more information about CVE-2022-34256 at the following link: [Adobe Security Bulletin APSB22-38](https://helpx.adobe.com/security/products/magento/apsb22-38.html).