CVE-2023-22248: Adobe Commerce Incorrect Authorization Security feature bypass
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to leak another user's data. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-22248?
CVE-2023-22248 is an Incorrect Authorization vulnerability in Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier), and 2.4.4-p3 (and earlier) that could result in a security feature bypass.
How does CVE-2023-22248 affect Adobe Commerce?
CVE-2023-22248 affects Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier), and 2.4.4-p3 (and earlier) by allowing an attacker to leak another user's data.
What is the severity of CVE-2023-22248?
The severity of CVE-2023-22248 is high, with a CVSS score of 7.5.
How can I fix CVE-2023-22248?
To fix CVE-2023-22248, update to Adobe Commerce versions 2.4.6-p1 (or later), 2.4.5-p3 (or later), or 2.4.4-p4 (or later).
Where can I find more information about CVE-2023-22248?
You can find more information about CVE-2023-22248 on the Adobe Security Bulletin APSB23-35.