CVE-2024-45118: Adobe Commerce | Improper Access Control (CWE-284)
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have high impact on integrity. Exploitation of this issue does not require user interaction.
Other sources
Magento Open Source versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have high impact on integrity. Exploitation of this issue does not require user interaction.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45118?
CVE-2024-45118 has been classified as a low severity vulnerability.
How do I fix CVE-2024-45118?
To resolve CVE-2024-45118, upgrade to Adobe Commerce version 2.4.4-p11, 2.4.5-p10, 2.4.6-p8, or 2.4.7-p3.
What types of attacks could exploit CVE-2024-45118?
CVE-2024-45118 can be exploited by low-privileged attackers to bypass security measures within affected versions.
Which versions are affected by CVE-2024-45118?
CVE-2024-45118 affects Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, and 2.4.4-p10 or earlier.
Is CVE-2024-45118 a critical issue that needs immediate action?
While CVE-2024-45118 is not critical, it is advisable to apply the necessary updates to maintain security.