CVE-2023-29291
Severity CVSS v4.0:
Pending analysis
Type:
CWE-918
Server-Side Request Forgery (SSRF)
Publication date:
15/06/2023
Last modified:
22/06/2023
Description
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. An admin-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction.
Impact
Base Score 3.x
4.90
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:adobe:commerce:2.3.7:-:*:*:*:*:*:* | ||
| cpe:2.3:a:adobe:commerce:2.3.7:p1:*:*:*:*:*:* | ||
| cpe:2.3:a:adobe:commerce:2.3.7:p2:*:*:*:*:*:* | ||
| cpe:2.3:a:adobe:commerce:2.3.7:p3:*:*:*:*:*:* | ||
| cpe:2.3:a:adobe:commerce:2.3.7:p4:*:*:*:*:*:* | ||
| cpe:2.3:a:adobe:commerce:2.3.7:p4-ext1:*:*:*:*:*:* | ||
| cpe:2.3:a:adobe:commerce:2.3.7:p4-ext2:*:*:*:*:*:* | ||
| cpe:2.3:a:adobe:commerce:2.4.0:-:*:*:*:*:*:* | ||
| cpe:2.3:a:adobe:commerce:2.4.0:ext-1:*:*:*:*:*:* | ||
| cpe:2.3:a:adobe:commerce:2.4.0:ext-2:*:*:*:*:*:* | ||
| cpe:2.3:a:adobe:commerce:2.4.1:-:*:*:*:*:*:* | ||
| cpe:2.3:a:adobe:commerce:2.4.1:ext-1:*:*:*:*:*:* | ||
| cpe:2.3:a:adobe:commerce:2.4.1:ext-2:*:*:*:*:*:* | ||
| cpe:2.3:a:adobe:commerce:2.4.2:-:*:*:*:*:*:* | ||
| cpe:2.3:a:adobe:commerce:2.4.2:ext-1:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



