CVE-2023-38209: Adobe Commerce Incorrect Authorization Security feature bypass
Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) are affected by an Incorrect Authorization vulnerability that could lead to a Security feature bypass. A low-privileged attacker could leverage this vulnerability to access other user's data. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-38209.
What is the severity level of CVE-2023-38209?
The severity level of CVE-2023-38209 is medium.
What is the affected software?
Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) are affected.
How does the vulnerability impact the affected software?
The vulnerability could lead to an Incorrect Authorization vulnerability that could allow a low-privileged attacker to access other user's data.
Is there a fix for CVE-2023-38209?
Yes, Adobe has released a security update to address the vulnerability. Users are advised to update to the latest version of Adobe Commerce.