CVE-2025-24432Time-of-check Time-of-use (TOCTOU) Race Condition in Adobe Commerce

Severity
3.7LOWNVD
EPSS
0.1%
top 71.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 11

Description

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this race condition to alter a condition after it has been checked but before it is used, potentially bypassing rate limiting mechanisms. Exploitation of this issue does not require user interaction.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 2.2 | Impact: 1.4

Affected Packages6 packages

NVDadobe/commerce< 2.4.4+5
NVDadobe/commerce_b2b< 1.3.3+5
CVEListV5adobe/adobe_commerce2.4.8-beta1
NVDadobe/magento< 2.4.4+5
Packagistmagento/community-edition2.4.7-beta12.4.7-p4+3

🔴Vulnerability Details

3
OSV
Magento Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability2025-02-11
CVEList
Adobe Commerce | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367)2025-02-11
GHSA
Magento Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability2025-02-11
CVE-2025-24432 — Adobe Commerce vulnerability | cvebase