Skip to content

Commit

Permalink
Merge pull request #5267 from github/ihor-sviziev-GHSA-fppq-f2m6-xv5c
Browse files Browse the repository at this point in the history
  • Loading branch information
advisory-database[bot] authored Feb 12, 2025
2 parents f269bbc + e737fa2 commit 4b1114f
Showing 1 changed file with 200 additions and 2 deletions.
Original file line number Diff line number Diff line change
@@ -1,19 +1,217 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fppq-f2m6-xv5c",
"modified": "2025-02-11T18:31:43Z",
"modified": "2025-02-11T18:31:49Z",
"published": "2025-02-11T18:31:43Z",
"aliases": [
"CVE-2025-24434"
],
"summary": "Improper Authorization vulnerability in Magento and Adobe Commerce - Security update available for Adobe Commerce | APSB25-08",
"details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "magento/community-edition"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "2.4.8-beta1"
},
{
"fixed": "2.4.8-beta2"
}
]
}
],
"versions": [
"2.4.8-beta1"
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "magento/community-edition"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "2.4.7-beta1"
},
{
"fixed": "2.4.7-p4"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "magento/community-edition"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "2.4.6-p1"
},
{
"fixed": "2.4.6-p9"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "magento/community-edition"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "2.4.5-p1"
},
{
"fixed": "2.4.5-p11"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "magento/community-edition"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "2.4.4-p12"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "magento/magento2-base"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "2.4.8-beta1"
},
{
"fixed": "2.4.8-beta2"
}
]
}
],
"versions": [
"2.4.8-beta1"
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "magento/magento2-base"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "2.4.7-beta1"
},
{
"fixed": "2.4.7-p4"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "magento/magento2-base"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "2.4.6-p1"
},
{
"fixed": "2.4.6-p9"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "magento/magento2-base"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "2.4.5-p1"
},
{
"fixed": "2.4.5-p11"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "magento/magento2-base"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "2.4.4-p12"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
Expand Down

0 comments on commit 4b1114f

Please sign in to comment.