CVE-2024-34102: Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability
Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution.
Other sources
Adobe Commerce and Magento Open Source could allow a remote attacker to execute arbitrary code on the system, caused by improper restriction of XML external entity (XXE) reference. By using a specially crafted XML content, a remote attacker could exploit this vulnerability to execute arbitrary code on the system or cause a denial of service.
— IBM
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/magento/community-editionto a version that resolves this vulnerability.Fixed in 2.4.4-p9 - Upgrade
Upgrade
composer/magento/community-editionto a version that resolves this vulnerability.Fixed in 2.4.5-p8 - Upgrade
Upgrade
composer/magento/community-editionto a version that resolves this vulnerability.Fixed in 2.4.6-p6
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34102?
CVE-2024-34102 is considered a critical vulnerability as it allows for remote code execution.
How do I fix CVE-2024-34102?
To mitigate CVE-2024-34102, upgrade Adobe Commerce or Magento Open Source to version 2.4.4-p9 or later.
Who is affected by CVE-2024-34102?
CVE-2024-34102 affects Adobe Commerce and Magento Open Source versions 2.4.2 to 2.4.7.
What type of vulnerability is CVE-2024-34102?
CVE-2024-34102 is classified as an improper restriction of XML external entity reference (XXE) vulnerability.
Can CVE-2024-34102 lead to data breaches?
Yes, CVE-2024-34102 can lead to data breaches as it allows attackers to execute arbitrary code on the affected systems.