CVE-2023-38251: Adobe Commerce | Uncontrolled Resource Consumption (CWE-400)
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by a Uncontrolled Resource Consumption vulnerability that could lead in minor application denial-of-service. Exploitation of this issue does not require user interaction.
Other sources
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Uncontrolled Resource Consumption vulnerability that could lead into a minor application denial-of-service. Exploitation of this issue does not require user interaction.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38251?
CVE-2023-38251 has a minor severity level associated with an uncontrolled resource consumption vulnerability.
How does CVE-2023-38251 affect Adobe Commerce applications?
CVE-2023-38251 can lead to minor application denial-of-service in affected versions of Adobe Commerce.
Which versions of Adobe Commerce are affected by CVE-2023-38251?
CVE-2023-38251 affects Adobe Commerce versions 2.4.7-beta1 and earlier, 2.4.6-p2 and earlier, 2.4.5-p4 and earlier, and 2.4.4-p5 and earlier.
How can I mitigate CVE-2023-38251 in my Adobe Commerce deployment?
To mitigate CVE-2023-38251, upgrading to the latest version of Adobe Commerce that is not affected is recommended.
Is there any known exploit for CVE-2023-38251?
As of now, there are no publicly known active exploits specifically targeting CVE-2023-38251.