CVE-2024-39399: [Paris] Path Traversal lead to local file read
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. A low-privileged attacker could exploit this vulnerability to gain access to files and directories that are outside the restricted directory. Exploitation of this issue does not require user interaction and scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39399?
CVE-2024-39399 has been classified with a severity level that may allow low-privileged attackers to exploit path traversal vulnerabilities.
How do I fix CVE-2024-39399?
To fix CVE-2024-39399, it is recommended to update Adobe Commerce to the latest patched version.
What versions are affected by CVE-2024-39399?
CVE-2024-39399 affects Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier.
What can an attacker do with CVE-2024-39399?
An attacker can exploit CVE-2024-39399 to perform arbitrary file system reads through path traversal.
Is there a workaround for CVE-2024-39399?
There are no documented workarounds for CVE-2024-39399 aside from upgrading to a patched version of Adobe Commerce.