CVE-2024-34102

Published Jun 13, 2024

Last updated 3 months ago

Overview

Description
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.
Source
psirt@adobe.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability
Exploit added on
Jul 17, 2024
Exploit action due
Aug 7, 2024
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weaknesses

psirt@adobe.com
CWE-611

Social media

Hype score
Not currently trending
  1. Over on #SplunkBlogs, the Splunk Threat Research Team breaks down CVE-2024-34102. Also known as CosmicSting, this vulnerability highlights the ongoing challenges in maintaining security in complex, widely-deployed software systems. https://t.co/6ewkyhy0bH https://t.co/kWdjEJbbOx

    @jenmeadzellner

    4 Dec 2024

    19 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Over on #SplunkBlogs, the Splunk Threat Research Team breaks down CVE-2024-34102. Also known as CosmicSting, this vulnerability highlights the ongoing challenges in maintaining security in complex, widely-deployed software systems. https://t.co/xzDzA3X1z3 https://t.co/IJOs61ygz7

    @Pav0ne

    3 Dec 2024

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Over on #SplunkBlogs, the Splunk Threat Research Team breaks down CVE-2024-34102. Also known as CosmicSting, this vulnerability highlights the ongoing challenges in maintaining security in complex, widely-deployed software systems. https://t.co/Uc50YmYwJz https://t.co/3dxPe0XM71

    @ayazahmed85

    28 Nov 2024

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Over on #SplunkBlogs, the Splunk Threat Research Team breaks down CVE-2024-34102. Also known as CosmicSting, this vulnerability highlights the ongoing challenges in maintaining security in complex, widely-deployed software systems. https://t.co/NHpvpa8CwU https://t.co/cDlaZJhXgP

    @henryvillar

    27 Nov 2024

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Over on #SplunkBlogs, the Splunk Threat Research Team breaks down CVE-2024-34102. Also known as CosmicSting, this vulnerability highlights the ongoing challenges in maintaining security in complex, widely-deployed software systems. https://t.co/ySZMZzntPi https://t.co/QLtDoNcQmN

    @oferguetta

    27 Nov 2024

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨 Unveiling CosmicSting: Post-Analysis of CVE-2024-34102! 🚨 Dive into our latest blog where we dissect CVE-2024-34102, a critical XXE vulnerability affecting Adobe Commerce and Magento, released earlier this year! 🛍️💥🔍 Highlights: 🌌 CosmicSting Decoded: In-depth look at…

    @M_haggis

    25 Nov 2024

    1925 Impressions

    8 Retweets

    10 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  7. TERCERA PISTA DEL CAPTURE THE FLAG DENTRO DE LA @BugCON ¿Ya leíste bien el apache? ¿Tok tok 8090? ¿Ya revisaste los archivos de backup? (Bak) CVE-2024-34102 #BugCON #HackersCentral #ctf

    @hackers_central

    22 Nov 2024

    154 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Understanding the CosmicSting CVE-2024-34102 Attack on Magento Open Source/ Adobe Commerce #fixnblog https://t.co/jSSB3WPvmj

    @FixnBlog

    18 Nov 2024

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Actively exploited CVE : CVE-2024-34102

    @transilienceai

    4 Nov 2024

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  10. Actively exploited CVE : CVE-2024-34102

    @transilienceai

    30 Oct 2024

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  11. Actively exploited CVE : CVE-2024-34102

    @transilienceai

    29 Oct 2024

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  12. Actively exploited CVE : CVE-2024-34102

    @transilienceai

    25 Oct 2024

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  13. Actively exploited CVE : CVE-2024-34102

    @transilienceai

    23 Oct 2024

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  14. 🔓A critical vulnerability dubbed #CosmicSting (CVE-2024-34102) is affecting #AdobeCommerce and #Magento e-commerce platforms. https://t.co/7HrllOeu2I https://t.co/mu3OryKlft

    @ecommbridgeeu

    21 Oct 2024

    20 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. Security Update: Magento/Adobe Commerce Hack - In the past 24 hours, over 2,000 Magento stores have been hacked, with the CosmicSting vulnerability (CVE-2024-34102) being the likely cause. If you're unsure about your store's security, reach out—we're here to help you stay safe. h

    @neverfray

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Actively exploited CVE : CVE-2024-34102

    @transilienceai

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  17. Actively exploited CVE : CVE-2024-34102

    @transilienceai

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

Configurations