Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
- Feiten
Adobe heeft kwetsbaarheden verholpen in Commerce en Magento.
- Interpretaties
De kwetsbaarheden stellen een kwaadwillende in staat aanvallen uit te voeren die leiden tot de volgende categorieën schade:
- Omzeilen van beveiligingsmaatregel
- Toegang tot gevoelige gegevens
- Toegang tot systeemgegevens
- Verhoogde gebruikersrechten
- (Remote) code execution (Gebruikersrechten)
- Oplossingen
Adobe heeft updates beschikbaar gesteld om de kwetsbaarheden te verhelpen. Zie bijgevoegde referentie voor meer informatie.
- Kans
medium
- Schade
high
- CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
- CWE-285
Improper Authorization
- CWE-284
Improper Access Control
- CWE-918
Server-Side Request Forgery (SSRF)
- CWE-863
Incorrect Authorization
- CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
- CWE-287
Improper Authentication
- CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard