CVE-2024-45120: Adobe Commerce | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367)
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to a security feature bypass. An attacker could exploit this vulnerability to alter a condition between the check and the use of a resource, having a low impact on integrity. Exploitation of this issue requires user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45120?
CVE-2024-45120 is a security feature bypass vulnerability with a high severity rating.
How do I fix CVE-2024-45120?
To fix CVE-2024-45120, update Adobe Commerce to versions 2.4.4-p11, 2.4.5-p10, 2.4.6-p8, or 2.4.7-p3.
Which versions of Adobe Commerce are affected by CVE-2024-45120?
Affected versions include Adobe Commerce 2.4.4-p10 and earlier, 2.4.5-p9 and earlier, 2.4.6-p7 and earlier, and 2.4.7-p2 and earlier.
What type of vulnerability is CVE-2024-45120?
CVE-2024-45120 is classified as a Time-of-check Time-of-use (TOCTOU) race condition vulnerability.
Can CVE-2024-45120 be exploited remotely?
Yes, an attacker can exploit CVE-2024-45120 remotely to bypass security features.