-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability description explicitly mentions manipulation of the connector API endpoint by authenticated admins. The most logical attack vector is the configuration save handler for these endpoints. While exact code isn't shown, Magento's architecture patterns place this functionality in admin configuration controllers. The PRODSECBUG-2309 reference confirms this relates to connector endpoint handling. SSRF would occur when saving malicious URLs to these endpoints without proper validation.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| magento/community-edition | composer | >= 2.2.0, < 2.2.10 | 2.2.10 |
| magento/community-edition | composer | >= 2.3.0, < 2.3.2-p2 | 2.3.2-p2 |
Ongoing coverage of React2Shell