VDB
Sign up
HIGH7.5

GHSA-5jfg-phx7-7fxg

Magento Open Source affected by Improper Input Validation

Quick fix

GHSA-5jfg-phx7-7fxg — magento/community-edition: upgrade to the fixed version with the command below.

composer require magento/community-edition:^2.4.5-p3

Details

Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to leak another user's data. Exploitation of this issue does not require user interaction.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/magento/community-edition

No fixed version published yet for magento/community-edition (composer). Pin to a known-safe version or switch to an alternative.

Packagist/magento/community-edition
Introduced in: 2.4.5-p1Fixed in: 2.4.5-p3
Fixcomposer require magento/community-edition:^2.4.5-p3
Packagist/magento/community-edition
Introduced in: 2.4.4-p1Fixed in: 2.4.5-p4
Fixcomposer require magento/community-edition:^2.4.5-p4
Packagist/magento/community-edition

No fixed version published yet for magento/community-edition (composer). Pin to a known-safe version or switch to an alternative.

Packagist/magento/community-edition

No fixed version published yet for magento/community-edition (composer). Pin to a known-safe version or switch to an alternative.

Packagist/magento/project-community-edition
Introduced in: 0

No fixed version published yet for magento/project-community-edition (composer). Pin to a known-safe version or switch to an alternative.

References