VDB

BIT-magento-2024-34111

BIT-magento-2024-34111 PUBLISHED CVSS 6.5 MEDIUM

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A low-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction..

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
Bitnamimagento2.4.7-alpha0, 2.4.6-alpha0, 2.4.5-alpha0

Timeline

  • Jun 17, 2024 CVE Published
  • Feb 26, 2025 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›