Arbitrary file upload in Magento Open Source and Adobe Commerce (formerly Magento Commerce) - CVE-2024-39397

 

Arbitrary file upload in Magento Open Source and Adobe Commerce (formerly Magento Commerce) - CVE-2024-39397

Published: August 13, 2024


Vulnerability identifier: #VU95942
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-39397
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to insufficient validation of file during file upload. A remote non-authenticated attacker can upload a malicious file and execute it on the server.

Successful exploitation of the vulnerability may result in entire system compromise.

Note, the vulnerability affects only installations with Apache HTTP server.


Affected software

Magento Open Source
Adobe Commerce (formerly Magento Commerce)

How to mitigate CVE-2024-39397

Install updates from vendor's website.

Magento Open Source - addressed in versions 2.4.4-p10, 2.4.5-p9, 2.4.6-p7, 2.4.7-p2
Adobe Commerce (formerly Magento Commerce) - addressed in versions 2.4.4-p10, 2.4.5-p9, 2.4.6-p7, 2.4.7-p2

External References

Related Security Bulletins