HIGH
Adobe Commerce Improper Access Control Privilege escalation
Published Aug 16, 2022
8.8
HIGHCVSS 3.1
EPSS 2.24%
Description
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in Privilege escalation. An attacker with a low privilege account could leverage this vulnerability to perform an account takeover for a victim. Exploitation of this issue does not require user interaction.
Affected products
-
Affected
- ≥ unspecified, ≤ 2.3.7-p3
- ≥ unspecified, ≤ 2.4.3-p2
- ≥ unspecified, ≤ 2.4.4
- ≥ unspecified, ≤ None
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Adobe | Magento Commerce | unknown | Affected
|
OR
- ≥ 2.3.0 · < 2.3.7
- ≥ 2.4.0 · < 2.4.3
- 2.3.7
- 2.3.7
- 2.3.7
- 2.3.7
- 2.4.3
- 2.4.3
- 2.4.3
- 2.4.4
- ≥ 2.3.0 · < 2.3.7
- ≥ 2.4.0 · < 2.4.3
- 2.3.7
- 2.3.7
- 2.3.7
- 2.3.7
- 2.4.3
- 2.4.3
- 2.4.3
- 2.4.4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-6643 Advisory
- https://github.com/advisories/GHSA-x95x-f4g9-mm85 Advisory
- https://github.com/magento/magento2/commit/246d524b7586af2245092008e0d92b8d6fdd8523
- https://github.com/magento/magento2/commit/5548bc64b5bc904346c0af9193a7fbb5274b4efa
- https://github.com/magento/magento2/commit/5f07eba878296a37bd5c3a2baecad48948547594
- https://helpx.adobe.com/security/products/magento/apsb22-38.html Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-34255
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner adobe
Published Aug 16, 2022
Updated Apr 23, 2025
Reserved Jun 21, 2022
Link CVE-2022-34255
CISA Vulnrichment
Updated Apr 23, 2025
Red Hat
No data
GitHub
Link GHSA-X95X-F4G9-MM85