CVE-2024-34108: Large attack surface through legit webhook usage in Adobe Commerce
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, but admin privileges are required and scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34108?
CVE-2024-34108 is classified as a critical severity vulnerability that allows arbitrary code execution.
How do I fix CVE-2024-34108?
To fix CVE-2024-34108, upgrade your Adobe Commerce installation to versions 2.4.7 or later, or apply the latest patches available.
Which versions are affected by CVE-2024-34108?
CVE-2024-34108 affects Adobe Commerce versions 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier, including version 2.3.7 and its patches.
Does CVE-2024-34108 require user interaction to exploit?
No, exploitation of CVE-2024-34108 does not require user interaction.
What type of vulnerability is CVE-2024-34108?
CVE-2024-34108 is an Improper Input Validation vulnerability.