Junglewise Threat Intelligence

CVE-2024-34102: Magento Open Source affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability

CVE-2024-34102 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2024-06-13

Technologies: Adobe Commerce, Adobe Magento Open Source. Vendors: Adobe.

Executive brief

Adobe Commerce and Magento Open Source are vulnerable to an Improper Restriction of XML External Entity Reference (XXE). An unauthenticated remote attacker can exploit this by sending crafted XML documents to achieve arbitrary code execution without user interaction.

Affected products

  • Adobe Commerce 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier
  • Adobe Magento Open Source 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier

Timeline

  • 2024-07-17: disclosed
  • 2024-07-17: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats