Umbra Wiki cve cve/CVE-2024-34102
Back to wiki

CVE-2024-34102 — Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability

provenance: imported · CVE: CVE-2024-34102

CVE-2024-34102: Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Adobe
Product Commerce and Magento Open Source
Date added 2024-07-17
Due date 2024-08-07
Ransomware campaign use Unknown

Description

Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution.

Required action (CISA)

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Notes

https://helpx.adobe.com/security/products/magento/apsb24-40.html; https://nvd.nist.gov/vuln/detail/CVE-2024-34102

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2024-34102
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog