CVE-2022-34259 is an Improper Access Control vulnerability affecting Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier), and 2.4.4 (and earlier), including Adobe Magento. This vulnerability allows an unauthenticated attacker to bypass security features and impact the availability of minor user features without user interaction. Rated Medium severity with a CVSS score of 5.3, the attack vector is network-based with low complexity, resulting in a low impact on availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.3.7-p3CPE match | cpe:2.3:a:adobe:magento_commerce:*:*:*:*:*:*:*:* | ||
<= 2.4.3-p2CPE match | cpe:2.3:a:adobe:magento_commerce:*:*:*:*:*:*:*:* | ||
<= 2.4.4CPE match | cpe:2.3:a:adobe:magento_commerce:*:*:*:*:*:*:*:* | ||
>= 2.3.0, < 2.3.7CPE matchmatch criteria | cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*:* | ||
>= 2.4.0, < 2.4.3CPE matchmatch criteria | cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.