CVE-2024-45128: Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on integrity and availability. Exploitation of this issue does not require user interaction.
Other sources
Magento Open Source versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on integrity and availability. Exploitation of this issue does not require user interaction.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45128?
CVE-2024-45128 has been classified as a low severity vulnerability.
How does CVE-2024-45128 allow an attacker to exploit Adobe Commerce?
CVE-2024-45128 allows a low-privileged attacker to bypass security measures resulting in a security feature bypass.
Which versions of Adobe Commerce are affected by CVE-2024-45128?
CVE-2024-45128 affects Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10, and earlier versions.
How can I fix CVE-2024-45128 in my Adobe Commerce installation?
To fix CVE-2024-45128, upgrade to Adobe Commerce version 2.4.4-p11, 2.4.5-p10, 2.4.6-p8, or 2.4.7-p3.
Is there a workaround for CVE-2024-45128?
Currently, no specific workaround is provided for CVE-2024-45128 apart from upgrading the affected versions.