CVE-2024-34107: Magento Open Source Improper Access Control vulnerability
5.3
CVSS Score
3.1
Basic Information
CVE ID
GHSA ID
EPSS Score
0.5496%
CWE
Published
6/13/2024
Updated
8/7/2024
KEV Status
No
Technology
PHP
Technical Details
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| magento/community-edition | composer | = 2.4.7 | |
| magento/community-edition | composer | = 2.4.6 | |
| magento/community-edition | composer | = 2.4.5 | |
| magento/community-edition | composer | = 2.4.4 | |
| magento/community-edition | composer | >= 2.4.6-p1, < 2.4.6-p6 | 2.4.6-p6 |
| magento/community-edition | composer | >= 2.4.5-p1, < 2.4.5-p8 | 2.4.5-p8 |
| magento/community-edition | composer | < 2.4.4-p9 | 2.4.4-p9 |