CVE-2024-34111: SSRF in service connector
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A low-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction..
Other sources
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted request to the server, which could then cause the server to execute arbitrary code. Exploitation of this issue does not require user interaction.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34111?
CVE-2024-34111 has a low severity rating, affecting versions of Adobe Commerce and exposing the system to potential server-side request forgery.
How do I fix CVE-2024-34111?
To remediate CVE-2024-34111, you should upgrade to Adobe Commerce version 2.4.4-p9 or later.
Which versions are affected by CVE-2024-34111?
CVE-2024-34111 affects Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier.
What is a Server-Side Request Forgery (SSRF) vulnerability in CVE-2024-34111?
In the context of CVE-2024-34111, SSRF allows an attacker to send unauthorized requests from the vulnerable server, potentially accessing sensitive resources.
Who can exploit CVE-2024-34111?
A low-privilege authenticated attacker can exploit CVE-2024-34111 to make arbitrary requests through the affected Adobe Commerce application.