CVE-2024-45148: Adobe Commerce | Improper Authentication (CWE-287)
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to gain unauthorized access without proper credentials. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45148?
CVE-2024-45148 is classified as a low severity vulnerability that can lead to improper authentication in Adobe Commerce.
How do I fix CVE-2024-45148?
To remediate CVE-2024-45148, update to the latest secure versions of Adobe Commerce provided by Adobe.
What versions of Adobe Commerce are affected by CVE-2024-45148?
CVE-2024-45148 affects Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier.
Who is impacted by CVE-2024-45148?
Low-privileged attackers who exploit this vulnerability can gain unauthorized access to Adobe Commerce instances.
Is my Adobe Magento Open Source vulnerable to CVE-2024-45148?
Yes, Adobe Magento Open Source versions that match the affected versions are also vulnerable to CVE-2024-45148.