CVE-2023-29296: [Cloud] Customer suspects IDOR vulnerability
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to modify a minor functionality of another user's data. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is Adobe Commerce vulnerability CVE-2023-29296?
Adobe Commerce versions 2.4.6 (and earlier) 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass.
What is the severity of CVE-2023-29296?
The severity of CVE-2023-29296 is medium with a CVSS score of 4.3.
How can an attacker exploit CVE-2023-29296?
A low-privileged attacker could leverage this vulnerability to modify a minor functionality of another part of the application.
Which versions of Adobe Commerce are affected by CVE-2023-29296?
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier), and 2.4.4-p3 (and earlier) are affected.
Is there a fix available for CVE-2023-29296?
Yes, Adobe has released a security advisory with a fix for this vulnerability.