Skip to main content
high CISA KEV

CVE-2024-34102

Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability

// Description

Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution.

// Required action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Federal remediation due Aug 7, 2024 — past due

Advertisement

// Coverage