Skip to content

Magento Improper Authorization vulnerability

High severity GitHub Reviewed Published Aug 17, 2022 to the GitHub Advisory Database • Updated Jan 11, 2024

Package

composer magento/community-edition (Composer)

Affected versions

>= 2.3.0, < 2.3.7-p4
>= 2.4.4, < 2.4.5
>= 2.4.0, < 2.4.3-p3

Patched versions

2.3.7-p4
2.4.5
2.4.3-p3

Description

Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to access other user's data. Exploitation of this issue does not require user interaction.

References

Published by the National Vulnerability Database Aug 16, 2022
Published to the GitHub Advisory Database Aug 17, 2022
Reviewed Jan 11, 2024
Last updated Jan 11, 2024

Severity

High
7.5
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVE ID

CVE-2022-34256

GHSA ID

GHSA-r7mm-grf3-5fjv

Source code

Checking history
See something to contribute? Suggest improvements for this vulnerability.