CVE-2020-24403
Incorrect permissions could lead to unauthorized modification of inventory source data via REST API
2.7
LOW
CVSS 3.1
EPSS 0.19%
Description
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect user permissions vulnerability within the Inventory component. This vulnerability could be abused by authenticated users with Inventory and Source permissions to make unauthorized changes to inventory source data via the REST API.
How to fix CVE-2020-24403
To remediate CVE-2020-24403, upgrade the affected package to a fixed version below.
- —upgrade to 2.3.5 or later
- —upgrade to 2.3.6 or later
- —no fix listed
Is CVE-2020-24403 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 2.3.5, >= 2.4.0, < 2.4.1
- from 0, < 2.3.6
- from 0, <= 2.0.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | LOW2.7 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N |