high
CISA KEV
CVE-2024-34102
Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability
// Description
Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution.
// Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Federal remediation due Aug 7, 2024 — past due
Advertisement