First published: Thu Jun 15 2023(Updated: )
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to modify a minor functionality of another user's data. Exploitation of this issue does not require user interaction.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Commerce | =2.3.7 | |
Adobe Commerce | =2.3.7-p1 | |
Adobe Commerce | =2.3.7-p2 | |
Adobe Commerce | =2.3.7-p3 | |
Adobe Commerce | =2.3.7-p4 | |
Adobe Commerce | =2.3.7-p4-ext1 | |
Adobe Commerce | =2.3.7-p4-ext2 | |
Adobe Commerce | =2.4.0 | |
Adobe Commerce | =2.4.0-ext-1 | |
Adobe Commerce | =2.4.0-ext-2 | |
Adobe Commerce | =2.4.1 | |
Adobe Commerce | =2.4.1-ext-1 | |
Adobe Commerce | =2.4.1-ext-2 | |
Adobe Commerce | =2.4.2 | |
Adobe Commerce | =2.4.2-ext-1 | |
Adobe Commerce | =2.4.2-ext-2 | |
Adobe Commerce | =2.4.3 | |
Adobe Commerce | =2.4.3-ext-1 | |
Adobe Commerce | =2.4.3-ext-2 | |
Adobe Commerce | =2.4.4 | |
Adobe Commerce | =2.4.4-p1 | |
Adobe Commerce | =2.4.4-p2 | |
Adobe Commerce | =2.4.4-p3 | |
Adobe Commerce | =2.4.5 | |
Adobe Commerce | =2.4.5-p1 | |
Adobe Commerce | =2.4.5-p2 | |
Adobe Commerce | =2.4.6 | |
Adobe Magento | =2.4.4 | |
Adobe Magento | =2.4.4-p1 | |
Adobe Magento | =2.4.4-p2 | |
Adobe Magento | =2.4.4-p3 | |
Adobe Magento | =2.4.5 | |
Adobe Magento | =2.4.5-p1 | |
Adobe Magento | =2.4.5-p2 | |
Adobe Magento | =2.4.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Adobe Commerce versions 2.4.6 (and earlier) 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass.
The severity of CVE-2023-29296 is medium with a CVSS score of 4.3.
A low-privileged attacker could leverage this vulnerability to modify a minor functionality of another part of the application.
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier), and 2.4.4-p3 (and earlier) are affected.
Yes, Adobe has released a security advisory with a fix for this vulnerability.