CVE-2024-34106: Insecure Direct Object Reference - An attacker can able to erase the victim quote details
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. An attacker could exploit this vulnerability to gain unauthorized access or perform actions with the privileges of another user. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34106?
CVE-2024-34106 is classified as a high severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2024-34106?
To remediate CVE-2024-34106, upgrade Adobe Commerce to version 2.4.4-p9 or later.
What versions are affected by CVE-2024-34106?
CVE-2024-34106 affects Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8, and earlier.
Can CVE-2024-34106 be exploited remotely?
Yes, an attacker can exploit CVE-2024-34106 remotely to gain unauthorized access.
Is CVE-2024-34106 related to authentication issues?
Yes, CVE-2024-34106 involves incorrect authorization, leading to potential security feature bypass.