CVE-2024-34102
Description
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.
Summary dbcve.org
Adobe Commerce contains an Improper Restriction of XML External Entity Reference (XXE) vulnerability in its XML parsing functionality. Attackers can send crafted XML documents containing external entity references to achieve arbitrary code execution on the affected system. This critical flaw affects versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier, and can be exploited without any user interaction.
Mitigation
Apply the vendor-released security patch or upgrade to a supported Adobe Commerce version that addresses this XXE vulnerability. Additionally, configure XML parsers to disable external entity processing as a defense-in-depth measure.