Published Jun 11, 2024.
XML external entity injection in the REST API (CVE-2024-34102), publicly known as CosmicSting. An unauthenticated attacker can read arbitrary files such as env.php and, chained with the glibc iconv bug CVE-2024-2961, execute code. Mass exploitation followed within weeks; Adobe also released an isolated patch for stores that could not upgrade.
| CVE | CVSS | Type | Impact | Auth required |
|---|---|---|---|---|
| CVE-2024-34102 | 9.8 | improper-restriction-of-xml-external-entity-reference | arbitrary-code-execution | no |
Get this bulletin as JSON:
curl -s https://magento.watch/api/v1/security-bulletins/APSB24-40
magento.watch is built and maintained by Łukasz Bajsarowicz, solo, on weekends. If it has saved you a few hours, consider chipping in.
Sponsor →Łukasz takes on Magento 2 and Adobe Commerce engagements — upgrades, audits, performance, team mentoring.
Get in touch →