CRITICAL

APSB25-08: Security update available for Adobe Commerce

Published Feb 11, 2025.

Improper authorization (CVE-2025-24434) that lets a low-privileged actor escalate privileges; Adobe rated it critical because exploitation does not require user interaction. Fixed in the February 2025 patch set.

Published
Feb 11, 2025
Severity
critical
CVEs
1
Isolated patch
no

CVEs

CVEs in APSB25-08
CVE CVSS Type Impact Auth required
CVE-2025-24434 8.8 improper-authorization privilege-escalation

Fixed in

Magento Open Source
2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12
Adobe Commerce
2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12
Mage-OS

References

For integrators

Get this bulletin as JSON:

curl -s https://magento.watch/api/v1/security-bulletins/APSB25-08