cbcvebase.
CVE-2022-42344
published 2022-10-20

CVE-2022-42344: Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Incorrect Authorization vulnerability. An…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Incorrect Authorization vulnerability. An authenticated attacker can exploit this vulnerability to achieve information exposure and privilege escalation.

Affected

13 ranges
VendorProductVersion rangeFixed in
adobecommerce< 2.3.72.3.7
adobecommerce
adobecommerce
adobecommerce
adobecommerce>= 2.4.0 < 2.4.32.4.3
magentocommunity-edition>= 0 < 2.3.7-p42.3.7-p4
magentocommunity-edition>= 2.4.0 < 2.4.3-p32.4.3-p3
magentocommunity-edition>= 2.4.4 < 2.4.52.4.5
magentomagento< 2.3.72.3.7
magentomagento
magentomagento
magentomagento
magentomagento>= 2.4.0 < 2.4.32.4.3