CVE-2024-34104: Adobe Commerce | Improper Authorization (CWE-285)
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access, leading to both confidentiality and integrity impact. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34104?
CVE-2024-34104 is classified as a high severity vulnerability due to its potential for allowing unauthorized access.
How do I fix CVE-2024-34104?
To fix CVE-2024-34104, update Adobe Commerce to version 2.4.4-p9 or later.
Which versions of Adobe Commerce are affected by CVE-2024-34104?
CVE-2024-34104 affects Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier.
What type of vulnerability is CVE-2024-34104?
CVE-2024-34104 is an Improper Authorization vulnerability that may lead to security feature bypass.
Can CVE-2024-34104 impact customer data?
Yes, if exploited, CVE-2024-34104 could result in unauthorized access, potentially impacting customer data.