CVE-2024-39412: Adobe Commerce | Improper Authorization (CWE-285)
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and perform a minor integrity change. Exploitation of this issue does not require user interaction.
Other sources
Magento Open Source versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and disclose minor information. Exploitation of this issue does not require user interaction.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39412?
CVE-2024-39412 has a low severity rating.
How do I fix CVE-2024-39412?
You can fix CVE-2024-39412 by upgrading to the latest patched version of Adobe Commerce, specifically 2.4.4-p10, 2.4.5-p9, 2.4.6-p7, or 2.4.7-p2.
Which Adobe Commerce versions are affected by CVE-2024-39412?
Adobe Commerce versions 2.4.4 through 2.4.7-p1 and earlier are affected by CVE-2024-39412.
What type of vulnerability is CVE-2024-39412?
CVE-2024-39412 is an Improper Authorization vulnerability that allows a low-privileged attacker to bypass security measures.
What could an attacker achieve by exploiting CVE-2024-39412?
An attacker could exploit CVE-2024-39412 to bypass security features and perform unauthorized actions within the affected Adobe Commerce systems.