Miggo Logo

CVE-2024-34107: Magento Open Source Improper Access Control vulnerability

5.3

CVSS Score
3.1

Basic Information

EPSS Score
0.5496%
Published
6/13/2024
Updated
8/7/2024
KEV Status
No
Technology
TechnologyPHP

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
magento/community-editioncomposer= 2.4.7
magento/community-editioncomposer= 2.4.6
magento/community-editioncomposer= 2.4.5
magento/community-editioncomposer= 2.4.4
magento/community-editioncomposer>= 2.4.6-p1, < 2.4.6-p62.4.6-p6
magento/community-editioncomposer>= 2.4.5-p1, < 2.4.5-p82.4.5-p8
magento/community-editioncomposer< 2.4.4-p92.4.4-p9

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

**o** *omm*r** v*rsions *.*.*, *.*.*-p*, *.*.*-p*, *.*.*-p* *n* **rli*r *r* *****t** *y *n Improp*r ****ss *ontrol vuln*r**ility t**t *oul* r*sult in * S**urity ***tur* *yp*ss. *n *tt**k*r *oul* l*v*r*** t*is vuln*r**ility to *yp*ss s**urity m**sur*s

Reasoning

No *n*lysis *v*il**l*
CVE-2024-34107: Magento Access Control Bypass | Miggo