Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to leak minor information of another user's account detials. Exploitation of this issue does not require user interaction.
[
{
"events": [
{
"introduced": "2.4.0"
},
{
"fixed": "2.4.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.3.7-NA"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.3.7-p1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.3.7-p2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.3.7-p3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.3-NA"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.3-p1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.3-p2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.4-NA"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-35692.json"