GHSA-m8cj-3v68-3cxj
Magento Open Source affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability
Quick fix
GHSA-m8cj-3v68-3cxj — magento/community-edition: upgrade to the fixed version with the command below.
composer require magento/community-edition:^2.4.6-p6Details
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for magento/community-edition (composer). Pin to a known-safe version or switch to an alternative.
2.4.6-p1Fixed in: 2.4.6-p6composer require magento/community-edition:^2.4.6-p62.4.5-p1Fixed in: 2.4.5-p8composer require magento/community-edition:^2.4.5-p80Fixed in: 2.4.4-p9composer require magento/community-edition:^2.4.4-p9No fixed version published yet for magento/community-edition (composer). Pin to a known-safe version or switch to an alternative.
No fixed version published yet for magento/community-edition (composer). Pin to a known-safe version or switch to an alternative.
No fixed version published yet for magento/community-edition (composer). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-34102[ADVISORY]
- https://github.com/magento/magento2/commit/30877fce83b793f71421c47347885cf076e81799[WEB]
- https://github.com/magento/magento2/commit/a3c6d6e5e95e63031e4df26cfcf76feace7549c2[WEB]
- https://github.com/magento/magento2/commit/c5c538810b87449886f4669cb8abbe8e5593c83c[WEB]
- https://github.com/magento/magento2/commit/d10435b11ada4e502dca7539f8fd31d059d3c482#diff-84a0773a6287fbbaadf3b9103f4a137fc0b6946de2437ddfd6f60a0722cf8d23[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/magento/product-community-edition/CVE-2024-34102.yaml[WEB]
- https://github.com/magento/magento2[PACKAGE]
- https://helpx.adobe.com/security/products/magento/apsb24-40.html[WEB]
- https://www.vicarius.io/vsociety/posts/cosmicsting-critical-unauthenticated-xxe-vulnerability-in-adobe-commerce-and-magento-cve-2024-34102[WEB]