Adobe Commerce Unrestricted Upload Vulnerability Could Lead to Arbitrary Code Execution
CVE-2024-39397

9CRITICAL

Key Information:

Vendor

Adobe

Vendor
CVE Published:
14 August 2024

What is CVE-2024-39397?

The vulnerability in Adobe Commerce relates to an unrestricted upload of files with dangerous types, allowing unauthorized actors to upload malicious files. This creates a significant risk as attackers can execute arbitrary code on the server hosting affected versions. The attack can be initiated without user interaction, although the complexity of the exploit is high. This vulnerability affects multiple versions of Adobe Commerce, highlighting the importance of prompt updates and security measures to protect against such exploits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Adobe Commerce 0 <= 2.4.4-p9

References

EPSS Score

9% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.