GHSA-hqgj-4396-hmxv

Suggest an improvement
Source
https://github.com/advisories/GHSA-hqgj-4396-hmxv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/02/GHSA-hqgj-4396-hmxv/GHSA-hqgj-4396-hmxv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-hqgj-4396-hmxv
Aliases
  • CVE-2024-20718
Published
2024-02-15T15:30:29Z
Modified
2025-03-04T18:57:02.215025Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N CVSS Calculator
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Magento Open Source allows Cross-Site Request Forgery (CSRF)
Details

Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to trick a victim into performing actions they did not intend to do, which could be used to bypass security measures and gain unauthorized access. Exploitation of this issue requires user interaction, typically in the form of the victim clicking a link or visiting a malicious website.

Database specific
{
    "nvd_published_at": "2024-02-15T14:15:45Z",
    "cwe_ids": [
        "CWE-352"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2025-03-04T18:30:32Z"
}
References

Affected packages

Packagist
magento/community-edition

Package

Name
magento/community-edition
Purl
pkg:composer/magento/community-edition

Affected ranges

Affected versions

2.*
2.4.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/02/GHSA-hqgj-4396-hmxv/GHSA-hqgj-4396-hmxv.json"
magento/community-edition

Package

Name
magento/community-edition
Purl
pkg:composer/magento/community-edition

Affected ranges

Affected versions

2.*
2.4.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/02/GHSA-hqgj-4396-hmxv/GHSA-hqgj-4396-hmxv.json"
magento/community-edition

Package

Name
magento/community-edition
Purl
pkg:composer/magento/community-edition

Affected ranges

Affected versions

2.*
2.4.4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/02/GHSA-hqgj-4396-hmxv/GHSA-hqgj-4396-hmxv.json"
magento/community-edition

Package

Name
magento/community-edition
Purl
pkg:composer/magento/community-edition

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.4.6-p1
Fixed
2.4.6-p4

Affected versions

2.*
2.4.6-p1
2.4.6-p2
2.4.6-p3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/02/GHSA-hqgj-4396-hmxv/GHSA-hqgj-4396-hmxv.json"
magento/community-edition

Package

Name
magento/community-edition
Purl
pkg:composer/magento/community-edition

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.4.5-p1
Fixed
2.4.5-p6

Affected versions

2.*
2.4.5-p1
2.4.5-p2
2.4.5-p3
2.4.5-p4
2.4.5-p5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/02/GHSA-hqgj-4396-hmxv/GHSA-hqgj-4396-hmxv.json"
magento/community-edition

Package

Name
magento/community-edition
Purl
pkg:composer/magento/community-edition

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.4.4-p1
Fixed
2.4.4-p7

Affected versions

2.*
2.4.4-p1
2.4.4-p2
2.4.4-p3
2.4.4-p4
2.4.4-p5
2.4.4-p6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/02/GHSA-hqgj-4396-hmxv/GHSA-hqgj-4396-hmxv.json"
magento/project-community-edition

Package

Name
magento/project-community-edition
Purl
pkg:composer/magento/project-community-edition

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.0.2

Affected versions

0.*
0.1.0-alpha89
0.1.0-alpha90
0.1.0-alpha91
0.1.0-alpha92
0.1.0-alpha93
0.1.0-alpha94
0.1.0-alpha95
0.1.0-alpha96
0.1.0-alpha97
0.1.0-alpha98
0.1.0-alpha99
0.1.0-alpha100
0.1.0-alpha101
0.1.0-alpha102
0.1.0-alpha103
0.1.0-alpha104
0.1.0-alpha105
0.1.0-alpha106
0.1.0-alpha107
0.1.0-alpha108
0.42.0-beta1
0.42.0-beta2
0.42.0-beta3
0.42.0-beta4
0.42.0-beta5
0.42.0-beta6
0.42.0-beta7
0.42.0-beta8
0.42.0-beta9
0.42.0-beta10
0.42.0-beta11
0.74.0-beta1
0.74.0-beta2
0.74.0-beta3
0.74.0-beta4
0.74.0-beta5
0.74.0-beta6
0.74.0-beta7
0.74.0-beta8
0.74.0-beta9
0.74.0-beta10
0.74.0-beta11
0.74.0-beta12
0.74.0-beta13
0.74.0-beta14
0.74.0-beta15
0.74.0-beta16
1.*
1.0.0-beta
2.*
2.0.0-rc
2.0.0-rc2
2.0.0
2.0.1
2.0.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/02/GHSA-hqgj-4396-hmxv/GHSA-hqgj-4396-hmxv.json"