CVE-2024-39417: An unauthorized user can export the Shipping Report
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and disclose minor information. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39417?
CVE-2024-39417 has a low severity rating as it involves an Improper Authorization vulnerability that could allow a low-privileged attacker to bypass security measures.
How do I fix CVE-2024-39417?
To fix CVE-2024-39417, update your Adobe Commerce or Magento installations to the latest available versions.
Which versions are affected by CVE-2024-39417?
CVE-2024-39417 affects Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9, and earlier versions.
What kind of attack can exploit CVE-2024-39417?
An attacker can exploit CVE-2024-39417 to bypass security features and potentially disclose sensitive information.
Is CVE-2024-39417 specific to Adobe Commerce or Magento Open Source?
CVE-2024-39417 affects both Adobe Commerce and Adobe Magento Open Source across specific versions.