Improper Authorization in Adobe Commerce (formerly Magento Commerce) and Magento Open Source - CVE-2022-34256
Published: August 10, 2022
Vulnerability identifier: #VU66377
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-34256
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The
vulnerability exists due to improper access restrictions. A remote
attacker can bypass implemented security restrictions and gain
unauthorized access to sensitive information.
Affected software
Adobe Commerce (formerly Magento Commerce)
Magento Open Source
Magento Open Source
How to mitigate CVE-2022-34256
Install updates from vendor's website.
Adobe Commerce (formerly Magento Commerce) - addressed in versions 2.3.7-p4, 2.4.3-p3, 2.4.4-p1, 2.4.5
Magento Open Source - addressed in versions 2.3.7-p4, 2.4.3-p3, 2.4.4-p1, 2.4.5
Magento Open Source - addressed in versions 2.3.7-p4, 2.4.3-p3, 2.4.4-p1, 2.4.5