CVE-2024-20720: Command injection in data collector backup due to insufficient patching of CVE-2023-38208
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/magento/community-editionto a version that resolves this vulnerability.Fixed in 2.4.4-p7 - Upgrade
Upgrade
composer/magento/community-editionto a version that resolves this vulnerability.Fixed in 2.4.5-p6 - Upgrade
Upgrade
composer/magento/community-editionto a version that resolves this vulnerability.Fixed in 2.4.6-p4
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20720?
CVE-2024-20720 is considered critical due to its potential for arbitrary code execution.
Which versions of Adobe Commerce are affected by CVE-2024-20720?
CVE-2024-20720 affects Adobe Commerce versions 2.4.4-p1 to 2.4.4-p6, 2.4.5 solutions, and 2.4.6 versions.
How do I fix CVE-2024-20720?
To remediate CVE-2024-20720, update Adobe Commerce to a patched version released after this vulnerability.
What type of vulnerability is CVE-2024-20720?
CVE-2024-20720 is an OS Command Injection vulnerability that can lead to arbitrary code execution.
Could CVE-2024-20720 be exploited by remote attackers?
Yes, CVE-2024-20720 can be exploited by remote attackers to execute arbitrary code.