CRITICAL

APSB24-73: Security update available for Adobe Commerce

Published Oct 8, 2024.

Improper authentication (CVE-2024-45115) that allows privilege escalation without prior authentication. Part of the October 2024 patch set that followed the CosmicSting exploitation wave.

Published
Oct 8, 2024
Severity
critical
CVEs
1
Isolated patch
no

CVEs

CVEs in APSB24-73
CVE CVSS Type Impact Auth required
CVE-2024-45115 9.8 improper-authentication privilege-escalation no

Fixed in

Magento Open Source
2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11
Adobe Commerce
2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11
Mage-OS

References

For integrators

Get this bulletin as JSON:

curl -s https://magento.watch/api/v1/security-bulletins/APSB24-73