Published Aug 13, 2024.
Unrestricted upload of a file with a dangerous type (CVE-2024-39397) allowing arbitrary code execution by an unauthenticated attacker; Adobe notes the exploit requires the Apache web server. Fixed in the August 2024 patch set.
| CVE | CVSS | Type | Impact | Auth required |
|---|---|---|---|---|
| CVE-2024-39397 | 9 | unrestricted-upload-of-file-with-dangerous-type | arbitrary-code-execution | no |
Get this bulletin as JSON:
curl -s https://magento.watch/api/v1/security-bulletins/APSB24-61
magento.watch is built and maintained by Łukasz Bajsarowicz, solo, on weekends. If it has saved you a few hours, consider chipping in.
Sponsor →Łukasz takes on Magento 2 and Adobe Commerce engagements — upgrades, audits, performance, team mentoring.
Get in touch →