8.4

CVE-2024-39401

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an admin attacker. Exploitation of this issue requires user interaction and scope is changed.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AdobeCommerce Version <= 2.4.3
AdobeCommerce Version2.4.4 Update-
AdobeCommerce Version2.4.4 Updatep1
AdobeCommerce Version2.4.4 Updatep2
AdobeCommerce Version2.4.4 Updatep3
AdobeCommerce Version2.4.4 Updatep4
AdobeCommerce Version2.4.4 Updatep5
AdobeCommerce Version2.4.4 Updatep6
AdobeCommerce Version2.4.4 Updatep7
AdobeCommerce Version2.4.4 Updatep8
AdobeCommerce Version2.4.4 Updatep9
AdobeCommerce Version2.4.5 Update-
AdobeCommerce Version2.4.5 Updatep1
AdobeCommerce Version2.4.5 Updatep2
AdobeCommerce Version2.4.5 Updatep3
AdobeCommerce Version2.4.5 Updatep4
AdobeCommerce Version2.4.5 Updatep5
AdobeCommerce Version2.4.5 Updatep6
AdobeCommerce Version2.4.5 Updatep7
AdobeCommerce Version2.4.5 Updatep8
AdobeCommerce Version2.4.6 Update-
AdobeCommerce Version2.4.6 Updatep1
AdobeCommerce Version2.4.6 Updatep2
AdobeCommerce Version2.4.6 Updatep3
AdobeCommerce Version2.4.6 Updatep4
AdobeCommerce Version2.4.6 Updatep5
AdobeCommerce Version2.4.6 Updatep6
AdobeCommerce Version2.4.7 Update-
AdobeCommerce Version2.4.7 Updateb1
AdobeCommerce Version2.4.7 Updateb2
AdobeCommerce Version2.4.7 Updatep1
AdobeMagento SwEditionopen_source Version <= 2.4.3
AdobeMagento Version2.4.4 Update- SwEditionopen_source
AdobeMagento Version2.4.4 Updatep1 SwEditionopen_source
AdobeMagento Version2.4.4 Updatep2 SwEditionopen_source
AdobeMagento Version2.4.4 Updatep3 SwEditionopen_source
AdobeMagento Version2.4.4 Updatep4 SwEditionopen_source
AdobeMagento Version2.4.4 Updatep5 SwEditionopen_source
AdobeMagento Version2.4.4 Updatep6 SwEditionopen_source
AdobeMagento Version2.4.4 Updatep7 SwEditionopen_source
AdobeMagento Version2.4.4 Updatep8 SwEditionopen_source
AdobeMagento Version2.4.4 Updatep9 SwEditionopen_source
AdobeMagento Version2.4.5 Update- SwEditionopen_source
AdobeMagento Version2.4.5 Updatep1 SwEditionopen_source
AdobeMagento Version2.4.5 Updatep2 SwEditionopen_source
AdobeMagento Version2.4.5 Updatep3 SwEditionopen_source
AdobeMagento Version2.4.5 Updatep4 SwEditionopen_source
AdobeMagento Version2.4.5 Updatep5 SwEditionopen_source
AdobeMagento Version2.4.5 Updatep6 SwEditionopen_source
AdobeMagento Version2.4.5 Updatep7 SwEditionopen_source
AdobeMagento Version2.4.5 Updatep8 SwEditionopen_source
AdobeMagento Version2.4.6 Update- SwEditionopen_source
AdobeMagento Version2.4.6 Updatep1 SwEditionopen_source
AdobeMagento Version2.4.6 Updatep2 SwEditionopen_source
AdobeMagento Version2.4.6 Updatep3 SwEditionopen_source
AdobeMagento Version2.4.6 Updatep4 SwEditionopen_source
AdobeMagento Version2.4.6 Updatep5 SwEditionopen_source
AdobeMagento Version2.4.6 Updatep6 SwEditionopen_source
AdobeMagento Version2.4.7 Update- SwEditionopen_source
AdobeMagento Version2.4.7 Updateb1 SwEditionopen_source
AdobeMagento Version2.4.7 Updateb2 SwEditionopen_source
AdobeMagento Version2.4.7 Updatep1 SwEditionopen_source
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.07% 0.77
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@adobe.com 8.4 1.7 6
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.