CRITICAL

APSB24-40: Security update available for Adobe Commerce

Published Jun 11, 2024.

XML external entity injection in the REST API (CVE-2024-34102), publicly known as CosmicSting. An unauthenticated attacker can read arbitrary files such as env.php and, chained with the glibc iconv bug CVE-2024-2961, execute code. Mass exploitation followed within weeks; Adobe also released an isolated patch for stores that could not upgrade.

Published
Jun 11, 2024
Severity
critical
CVEs
1
Isolated patch
yes

CVEs

CVEs in APSB24-40
CVE CVSS Type Impact Auth required
CVE-2024-34102 9.8 improper-restriction-of-xml-external-entity-reference arbitrary-code-execution no

Fixed in

Magento Open Source
2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9
Adobe Commerce
2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9
Mage-OS

Isolated patches

References

For integrators

Get this bulletin as JSON:

curl -s https://magento.watch/api/v1/security-bulletins/APSB24-40