First published: Thu Oct 20 2022(Updated: )
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an improper input validation vulnerability. An authenticated attacker can trigger an insecure direct object reference in the `V1/customers/me` endpoint to achieve information exposure and privilege escalation.
Credit: psirt@adobe.com psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Commerce | <2.3.7 | |
Adobe Commerce | >=2.4.0<2.4.3 | |
Adobe Commerce | =2.3.7 | |
Adobe Commerce | =2.3.7-p1 | |
Adobe Commerce | =2.3.7-p2 | |
Adobe Commerce | =2.3.7-p3 | |
Adobe Commerce | =2.4.3 | |
Adobe Commerce | =2.4.3-p1 | |
Adobe Commerce | =2.4.3-p2 | |
Adobe Commerce | =2.4.4 | |
Magento Magento | <2.3.7 | |
Magento Magento | >=2.4.0<2.4.3 | |
Magento Magento | =2.3.7 | |
Magento Magento | =2.3.7-p1 | |
Magento Magento | =2.3.7-p2 | |
Magento Magento | =2.3.7-p3 | |
Magento Magento | =2.4.3 | |
Magento Magento | =2.4.3-p1 | |
Magento Magento | =2.4.3-p2 | |
Magento Magento | =2.4.4 | |
composer/magento/community-edition | =2.4.4 | 2.4.5 |
composer/magento/community-edition | >=2.4.0<2.4.3-p3 | 2.4.3-p3 |
composer/magento/community-edition | <2.3.7-p4 | 2.3.7-p4 |
<2.3.7 | ||
>=2.4.0<2.4.3 | ||
=2.3.7 | ||
=2.3.7-p1 | ||
=2.3.7-p2 | ||
=2.3.7-p3 | ||
=2.4.3 | ||
=2.4.3-p1 | ||
=2.4.3-p2 | ||
=2.4.4 | ||
<2.3.7 | ||
>=2.4.0<2.4.3 | ||
=2.3.7 | ||
=2.3.7-p1 | ||
=2.3.7-p2 | ||
=2.3.7-p3 | ||
=2.4.3 | ||
=2.4.3-p1 | ||
=2.4.3-p2 | ||
=2.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-42344.
The severity of CVE-2022-42344 is high with a severity value of 8.8.
The affected software for CVE-2022-42344 is Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier), and 2.4.4 (and earlier).
CVE-2022-42344 allows an authenticated attacker to trigger an insecure direct object reference in the V1/customers/me endpoint, leading to information exposure.
Yes, Adobe has released a security update to address the vulnerability. Please refer to the reference link for more information.