Skip to content
COOEY

EXPOSURES › CVE-2024-34102

CVE-2024-34102

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-07-17 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-34102 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 rceexploited-in-wildsupply-chain

Adobe Commerce and Magento Open Source contain an XXE vulnerability that enables remote code execution.

This improperly restricted XXE vulnerability allows remote attackers to execute arbitrary code, posing a severe risk to DIB organizations relying on Adobe Commerce for e-commerce platforms. The vulnerability is actively exploited in the wild, necessitating immediate patching to prevent unauthorized access and data exfiltration.

Shame score — Active exploitation of a known RCE vulnerability in a widely used e-commerce platform indicates a critical security oversight.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution.

AFFECTED FEDRAMP PRODUCTS · 8
PRODUCTSTATUS
Adobe Acrobat Sign for Government
Adobe
Authorized
Adobe Analytics
Adobe
Authorized
Adobe Campaign
Adobe
Authorized
Adobe Connect Managed Services (ACMS-GC)
Adobe
Authorized
Adobe Creative Cloud for Enterprise
Adobe
Authorized
Adobe Document Cloud (PDF Services & Adobe Sign)
Adobe
Authorized
Adobe Experience Manager Managed Services (AEMMS-GC)
Adobe
Authorized
Adobe Learning Manager
Adobe
Authorized