First published: Thu Jun 15 2023(Updated: )
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An admin privileged attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of this issue does not require user interaction.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Commerce | =2.3.7 | |
Adobe Commerce | =2.3.7-p1 | |
Adobe Commerce | =2.3.7-p2 | |
Adobe Commerce | =2.3.7-p3 | |
Adobe Commerce | =2.3.7-p4 | |
Adobe Commerce | =2.3.7-p4-ext1 | |
Adobe Commerce | =2.3.7-p4-ext2 | |
Adobe Commerce | =2.4.0 | |
Adobe Commerce | =2.4.0-ext-1 | |
Adobe Commerce | =2.4.0-ext-2 | |
Adobe Commerce | =2.4.1 | |
Adobe Commerce | =2.4.1-ext-1 | |
Adobe Commerce | =2.4.1-ext-2 | |
Adobe Commerce | =2.4.2 | |
Adobe Commerce | =2.4.2-ext-1 | |
Adobe Commerce | =2.4.2-ext-2 | |
Adobe Commerce | =2.4.3 | |
Adobe Commerce | =2.4.3-ext-1 | |
Adobe Commerce | =2.4.3-ext-2 | |
Adobe Commerce | =2.4.4 | |
Adobe Commerce | =2.4.4-p1 | |
Adobe Commerce | =2.4.4-p2 | |
Adobe Commerce | =2.4.4-p3 | |
Adobe Commerce | =2.4.5 | |
Adobe Commerce | =2.4.5-p1 | |
Adobe Commerce | =2.4.5-p2 | |
Adobe Commerce | =2.4.6 | |
Adobe Magento | =2.4.4 | |
Adobe Magento | =2.4.4-p1 | |
Adobe Magento | =2.4.4-p2 | |
Adobe Magento | =2.4.4-p3 | |
Adobe Magento | =2.4.5 | |
Adobe Magento | =2.4.5-p1 | |
Adobe Magento | =2.4.5-p2 | |
Adobe Magento | =2.4.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-29293.
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier), and 2.4.4-p3 (and earlier) are affected by this vulnerability.
CVE-2023-29293 has a severity level of 2.7, which is considered low.
This vulnerability could result in a security feature bypass and impact the availability of a user.
You can find more information about this vulnerability at the following link: [Adobe Security Bulletin APSB23-35](https://helpx.adobe.com/security/products/magento/apsb23-35.html).