Adobe has announced a critical vulnerability affecting Adobe Commerce and Magento Open Source. Adobe Commerce merchants have been attacked, and exploitation of this vulnerability is rampant.
An important detail of the vulnerability shared by Adobe is that a successful exploit can be performed without authentication.
This means that an attacker can exploit the vulnerability without obtaining user login privileges.
The second detail shared by Adobe about this vulnerability is that admin rights are not required to exploit this vulnerability.
Adobe Vulnerability Rating
Adobe publishes three vulnerability rating metrics:
- Common Vulnerability Scoring System (CVSS)
- priorities
- Vulnerability level
Common Vulnerability Scoring System (CVSS)
The Common Vulnerability Scoring System (CVSS) is a non-profit organization (first organization) to score vulnerabilities on a scale of 1 to 10.
A score of 1 indicates the least concern, and a score of 10 indicates the highest severity of the vulnerability.
The Adobe Commerce and Magento vulnerabilities have a CVSS score of 9.8.
Vulnerability priority
The priority metric has three levels, 1, 2, and 3. Level 1 is the most severe and level 3 is the least severe.
Adobe has prioritized this exploit as 1, the highest level.
A priority of 1 means that the vulnerability is being actively exploited in the website.
This is the worst-case scenario for merchants, as it means unpatched Adobe Commerce and Magento instances are vulnerable to hacking.
Adobe’s definition of Priority 1 is:
“This update addresses targeted vulnerabilities or vulnerabilities with a higher risk of being targeted through in-the-wild exploits for a given product version and platform.
Adobe recommends that administrators install the update as soon as possible. (for example, within 72 hours). “
Vulnerability level
Adobe’s vulnerability levels are named Moderate, Important, and Critical, with Critical representing the most dangerous level.
The vulnerability level assigned to Adobe Commerce and Magento open source exploits is rated Critical, the most dangerous rating level.
Definition of Adobe The key rating levels are:
“A vulnerability, if exploited, could allow malicious native code to be executed without the user’s knowledge.”
Arbitrary Code Execution Vulnerability
What makes this vulnerability particularly worrisome is that Adobe admits it is an arbitrary code execution vulnerability.
Arbitrary code execution generally means that the type of code an attacker can run is not limited in scope, but is basically open to any code they want in order to perform almost any task or command they want.
Arbitrary code execution vulnerabilities are a very serious type of attack.
Which versions are affected
Adobe has announced the release of an update patch to fix affected software versions.
This Update release notes statement:
“These patches have been tested to address all versions from 2.3.3-p1 to 2.3.7-p2 and from 2.4.0 to 2.4.3-p1.”
The major vulnerability bulletin states that Adobe Commerce 2.3.3 and earlier versions are not affected. https://helpx.adobe.com/security/products/magento/apsb22-12.html
Adobe advises users of affected software to update their installations immediately.
Citation
Read the Adobe Security Bulletin
Security Updates for Adobe Commerce | APSB22-12
Read Adobe Commerce and Magento Open Source Patch Release Notes
Security Update for Adobe Commerce APSB22-12
Information about exploit severity ratings
!function(f,b,e,v,n,t,s) {if(f.fbq)return;n=f.fbq=function(){n.callMethod? n.callMethod.apply(n,arguments):n.queue.push(arguments)}; if(!f._fbq)f._fbq=n;n.push=n;n.loaded=!0;n.version='2.0'; n.queue=[];t=b.createElement(e);t.async=!0; t.src=v;s=b.getElementsByTagName(e)[0]; s.parentNode.insertBefore(t,s)}(window,document,'script', 'https://connect.facebook.net/en_US/fbevents.js');
if( typeof sopp !== "undefined" && sopp === 'yes' ){ fbq('dataProcessingOptions', ['LDU'], 1, 1000); }else{ fbq('dataProcessingOptions', []); }
fbq('init', '1321385257908563');
fbq('track', 'PageView');
fbq('trackSingle', '1321385257908563', 'ViewContent', { content_name: 'magento-adobe-commerce-vulnerability', content_category: 'news web-development ' });



