CVE-2022-34259: Adobe Commerce Improper Access Control Security feature bypass
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-34259.
What versions of Adobe Commerce are affected by the vulnerability?
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier), and 2.4.4 (and earlier) are affected.
What is the severity of CVE-2022-34259?
The severity of CVE-2022-34259 is medium with a CVSS score of 5.3.
What is the impact of the vulnerability?
The vulnerability could result in a Security feature bypass and impact the availability of a user's minor feature.
How can I fix the vulnerability?
It is recommended to update Adobe Commerce to versions 2.4.3-p3, 2.3.7-p4, or 2.4.4-p1 to fix the vulnerability.