CVE-2023-38220: Full page cache enumeration via cookie X-Magento-Vary
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Improper Authorization vulnerability that could lead in a security feature bypass in a way that an attacker could access unauthorised data. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38220?
CVE-2023-38220 has been classified as a high severity vulnerability due to its potential to bypass security features and access unauthorized data.
How do I fix CVE-2023-38220?
To fix CVE-2023-38220, you should update your Adobe Commerce to version 2.4.7 or 2.4.6-p3 and later, or apply the latest security patches.
What types of Adobe Commerce versions are affected by CVE-2023-38220?
Affected versions include Adobe Commerce 2.4.7-beta1 and earlier, 2.4.6-p2 and earlier, 2.4.5-p4 and earlier, and 2.4.4-p5 and earlier.
Can CVE-2023-38220 be exploited remotely?
Yes, CVE-2023-38220 can be exploited remotely by an attacker to gain access to unauthorized data.
What potential impact does CVE-2023-38220 have?
The impact of CVE-2023-38220 includes data breaches and unauthorized access to sensitive information in affected Adobe Commerce installations.