CVE-2023-29287: Adobe Commerce Information Exposure Security feature bypass
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Information Exposure vulnerability that could lead to a security feature bypass. An attacker could leverage this vulnerability to leak minor user data. Exploitation of this issue does not require user interaction..
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-29287?
The severity of CVE-2023-29287 is medium with a CVSS score of 5.3.
How does CVE-2023-29287 affect Adobe Commerce?
CVE-2023-29287 affects Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier), and 2.4.4-p3 (and earlier).
What is the vulnerability description of CVE-2023-29287?
CVE-2023-29287 is an Information Exposure vulnerability in Adobe Commerce that could lead to a security feature bypass and minor user data leakage.
How can an attacker exploit CVE-2023-29287?
An attacker can exploit CVE-2023-29287 to leak minor user data and potentially bypass security features.
Where can I find more information about CVE-2023-29287?
You can find more information about CVE-2023-29287 on the Adobe Security Bulletin APSB23-35.