CVE-2024-34107: Adobe Commerce | Improper Access Control (CWE-284)
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.
Other sources
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and view minor unauthorised information. Exploitation of this issue does not require user interaction.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34107?
CVE-2024-34107 is classified as a critical vulnerability due to its potential to bypass security measures in Adobe Commerce.
How do I fix CVE-2024-34107?
To fix CVE-2024-34107, upgrade Adobe Commerce to version 2.4.4-p9 or later, 2.4.5-p8 or later, or 2.4.6-p6 or later.
What types of attacks can exploit CVE-2024-34107?
Attackers can exploit CVE-2024-34107 to gain unauthorized access by bypassing access control mechanisms.
Which versions of Adobe Commerce are affected by CVE-2024-34107?
CVE-2024-34107 affects Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier.
Is it possible to mitigate risks associated with CVE-2024-34107 without updating?
While the best practice is to update to a non-vulnerable version, temporarily enhancing access controls and monitoring can mitigate some risk.