CRITICAL

APSB24-18: Security update available for Adobe Commerce

Published Apr 9, 2024.

Improper input validation (CVE-2024-20758) enabling arbitrary code execution by an authenticated administrator, plus stored cross-site scripting (CVE-2024-20759). Published with the 2.4.7 general availability release and the April 2024 patch set.

Published
Apr 9, 2024
Severity
critical
CVEs
2
Isolated patch
no

CVEs

CVEs in APSB24-18
CVE CVSS Type Impact Auth required
CVE-2024-20758 9.1 improper-input-validation arbitrary-code-execution yes
CVE-2024-20759 cross-site-scripting-stored

Fixed in

Magento Open Source
2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8
Adobe Commerce
2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8
Mage-OS

References

For integrators

Get this bulletin as JSON:

curl -s https://magento.watch/api/v1/security-bulletins/APSB24-18