5.5

CVE-2020-24402

Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability in the Integrations component. This vulnerability could be abused by authenticated users with permissions to the Resource Access API to delete customer details via the REST API without authorization.

Data is provided by the National Vulnerability Database (NVD)
MagentoMagento SwEditioncommerce Version < 2.3.5
MagentoMagento SwEditionopen_source Version < 2.3.5
MagentoMagento Version2.3.5 Update- SwEditioncommerce
MagentoMagento Version2.3.5 Update- SwEditionopen_source
MagentoMagento Version2.3.5 Updatep1 SwEditioncommerce
MagentoMagento Version2.3.5 Updatep1 SwEditionopen_source
MagentoMagento Version2.4.0 SwEditioncommerce
MagentoMagento Version2.4.0 SwEditionopen_source
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.19% 0.412
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.5 8 4.9
AV:N/AC:L/Au:S/C:N/I:P/A:P
nvd@nist.gov 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
psirt@adobe.com 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.