CRITICAL

APSB24-61: Security update available for Adobe Commerce

Published Aug 13, 2024.

Unrestricted upload of a file with a dangerous type (CVE-2024-39397) allowing arbitrary code execution by an unauthenticated attacker; Adobe notes the exploit requires the Apache web server. Fixed in the August 2024 patch set.

Published
Aug 13, 2024
Severity
critical
CVEs
1
Isolated patch
no

CVEs

CVEs in APSB24-61
CVE CVSS Type Impact Auth required
CVE-2024-39397 9 unrestricted-upload-of-file-with-dangerous-type arbitrary-code-execution no

Fixed in

Magento Open Source
2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10
Adobe Commerce
2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10
Mage-OS

References

For integrators

Get this bulletin as JSON:

curl -s https://magento.watch/api/v1/security-bulletins/APSB24-61