Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PRP: Request Adobe Commerce RCE(CVE-2024-20720) #462

Closed
W0ngL1 opened this issue Apr 8, 2024 · 2 comments
Closed

PRP: Request Adobe Commerce RCE(CVE-2024-20720) #462

W0ngL1 opened this issue Apr 8, 2024 · 2 comments

Comments

@W0ngL1
Copy link
Contributor

W0ngL1 commented Apr 8, 2024

Hi there.

I would like to start implementing a plugin to detect Adobe Commerce RCE, CVE-2024-20720.

Reference:
https://nvd.nist.gov/vuln/detail/CVE-2024-20720
https://helpx.adobe.com/security/products/magento/apsb24-03.html

Description:
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction.

Versions:
2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier

Thanks.

@tooryx
Copy link
Member

tooryx commented May 22, 2024

Hi @W0ngL1,

For now we are not interested in that vulnerability.
As always, thank you for willing to contribute! Feel free to open new issues for other ideas that you might have.

~tooryx

@tooryx tooryx closed this as not planned Won't fix, can't repro, duplicate, stale May 22, 2024
@W0ngL1
Copy link
Contributor Author

W0ngL1 commented May 23, 2024

Copy that.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants