CVE-2023-29292: Server Side Request Forgery (SSRF) in FedEx carrier integration configuration
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. An admin-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-29292?
CVE-2023-29292 is a Server-Side Request Forgery (SSRF) vulnerability in Adobe Commerce versions 2.4.6 and earlier, 2.4.5-p2 and earlier, and 2.4.4-p3 and earlier.
What is the severity of CVE-2023-29292?
The severity of CVE-2023-29292 is medium with a CVSS score of 4.9.
How does CVE-2023-29292 affect Adobe Commerce?
CVE-2023-29292 allows an admin-privileged authenticated attacker to perform arbitrary file system reads through a Server-Side Request Forgery (SSRF) vulnerability.
Which versions of Adobe Commerce are affected by CVE-2023-29292?
Adobe Commerce versions 2.4.6 and earlier, 2.4.5-p2 and earlier, and 2.4.4-p3 and earlier are affected by CVE-2023-29292.
How can I fix CVE-2023-29292 vulnerability?
To fix CVE-2023-29292, update Adobe Commerce to the latest patched version available.