CVE-2023-29291: Server Side Request Forgery (SSRF) in USPS carrier integration configuration
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. An admin-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-29291?
CVE-2023-29291 is a Server-Side Request Forgery (SSRF) vulnerability affecting Adobe Commerce versions 2.4.6 and earlier, 2.4.5-p2 and earlier, and 2.4.4-p3 and earlier.
What is the severity of CVE-2023-29291?
The severity of CVE-2023-29291 is rated as medium with a severity value of 4.9.
How does CVE-2023-29291 impact Adobe Commerce?
CVE-2023-29291 allows an admin-privilege authenticated attacker to force the application to make arbitrary requests, leading to a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read.
Which versions of Adobe Commerce are affected by CVE-2023-29291?
Adobe Commerce versions 2.4.6 and earlier, 2.4.5-p2 and earlier, and 2.4.4-p3 and earlier are affected by CVE-2023-29291.
How can I fix CVE-2023-29291?
To fix CVE-2023-29291, it is recommended to update Adobe Commerce to the latest version available, specifically versions 2.4.7, 2.4.6-p1, and 2.4.5-p2.