Umbra Wiki cve cve/CVE-2022-24086
Back to wiki

CVE-2022-24086 — Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability

provenance: imported · CVE: CVE-2022-24086

CVE-2022-24086: Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Adobe
Product Commerce and Magento Open Source
Date added 2022-02-15
Due date 2022-03-01
Ransomware campaign use Unknown

Description

Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2022-24086

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2022-24086
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog