CVE-2024-20716: Force high-usage of resources by generating unlimited coupons: Adobe Commerce
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to an application denial-of-service. A high-privileged attacker could leverage this vulnerability to exhaust system resources, causing the application to slow down or crash. Exploitation of this issue does not require user interaction.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/magento/community-editionto a version that resolves this vulnerability.Fixed in 2.4.4-p7 - Upgrade
Upgrade
composer/magento/community-editionto a version that resolves this vulnerability.Fixed in 2.4.5-p6 - Upgrade
Upgrade
composer/magento/community-editionto a version that resolves this vulnerability.Fixed in 2.4.6-p4
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20716?
CVE-2024-20716 is classified as a high severity Uncontrolled Resource Consumption vulnerability.
How do I fix CVE-2024-20716?
To fix CVE-2024-20716, upgrade to the latest version of Adobe Commerce that addresses this vulnerability.
Which versions of Adobe Commerce are affected by CVE-2024-20716?
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by CVE-2024-20716.
What type of attack does CVE-2024-20716 facilitate?
CVE-2024-20716 could potentially lead to an application denial-of-service.
Who can exploit CVE-2024-20716?
A high-privileged attacker could leverage CVE-2024-20716 to exhaust system resources.