First published: Thu Jun 15 2023(Updated: )
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. An admin-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Commerce | =2.3.7 | |
Adobe Commerce | =2.3.7-p1 | |
Adobe Commerce | =2.3.7-p2 | |
Adobe Commerce | =2.3.7-p3 | |
Adobe Commerce | =2.3.7-p4 | |
Adobe Commerce | =2.3.7-p4-ext1 | |
Adobe Commerce | =2.3.7-p4-ext2 | |
Adobe Commerce | =2.4.0 | |
Adobe Commerce | =2.4.0-ext-1 | |
Adobe Commerce | =2.4.0-ext-2 | |
Adobe Commerce | =2.4.1 | |
Adobe Commerce | =2.4.1-ext-1 | |
Adobe Commerce | =2.4.1-ext-2 | |
Adobe Commerce | =2.4.2 | |
Adobe Commerce | =2.4.2-ext-1 | |
Adobe Commerce | =2.4.2-ext-2 | |
Adobe Commerce | =2.4.3 | |
Adobe Commerce | =2.4.3-ext-1 | |
Adobe Commerce | =2.4.3-ext-2 | |
Adobe Commerce | =2.4.4 | |
Adobe Commerce | =2.4.4-p1 | |
Adobe Commerce | =2.4.4-p2 | |
Adobe Commerce | =2.4.4-p3 | |
Adobe Commerce | =2.4.5 | |
Adobe Commerce | =2.4.5-p1 | |
Adobe Commerce | =2.4.5-p2 | |
Adobe Commerce | =2.4.6 | |
Adobe Magento | =2.4.4 | |
Adobe Magento | =2.4.4-p1 | |
Adobe Magento | =2.4.4-p2 | |
Adobe Magento | =2.4.4-p3 | |
Adobe Magento | =2.4.5 | |
Adobe Magento | =2.4.5-p1 | |
Adobe Magento | =2.4.5-p2 | |
Adobe Magento | =2.4.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-29291 is a Server-Side Request Forgery (SSRF) vulnerability affecting Adobe Commerce versions 2.4.6 and earlier, 2.4.5-p2 and earlier, and 2.4.4-p3 and earlier.
The severity of CVE-2023-29291 is rated as medium with a severity value of 4.9.
CVE-2023-29291 allows an admin-privilege authenticated attacker to force the application to make arbitrary requests, leading to a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read.
Adobe Commerce versions 2.4.6 and earlier, 2.4.5-p2 and earlier, and 2.4.4-p3 and earlier are affected by CVE-2023-29291.
To fix CVE-2023-29291, it is recommended to update Adobe Commerce to the latest version available, specifically versions 2.4.7, 2.4.6-p1, and 2.4.5-p2.