Adobe patches Magento CMS zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-24086 | Unauthenticated RCE via checkout input-validation flaw in Adobe Commerce/Magento Adobe Commerce and Magento Open Source versions 2.4.3-p1 and earlier and 2.3.7-p2 and earlier contain an improper input validation flaw (CWE-20) in the checkout process. A remote attacker can trigger it with no privileges and no user interaction by submitting crafted input to a store's checkout flow, and successful exploitation results in arbitrary code execution on the server hosting the storefront. Any Adobe Commerce or Magento Open Source storefront running the affected versions is exposed, and because these are internet-facing e-commerce sites the practical exposure is broad. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-02-15), its EPSS exploitation probability is 99.2% (100th percentile), and news reports describe ongoing attacks against Magento 2 stores, including recurring 'Xurum' attack campaigns and template-based attacks. Do: Upgrade every store to an Adobe-patched release per the vendor's instructions - i.e., any release newer than 2.4.3-p1 on the 2.4.x line or newer than 2.3.7-p2 on the 2.3.x line - noting that headlines indicate companion Magento CVEs were fixed in the same patch release, so consult Adobe's advisory for the full list. Because exploitation is unauthenticated and confirmed in the wild, prioritize internet-facing shops; WAF rules may reduce risk, but reports indicate WAF bypasses in related Magento attacks, so patching is the only reliable fix. After patching, review web server and application logs for exploitation attempts against the checkout flow and check affected hosts for indicators of compromise. | 9.8 | 99% | KEV |
| massroughly 100,000-300,000 online storefronts (Magento/Adobe Commerce is among the most widely deployed e-commerce platforms) |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | naturalfreshmall.com | f malware. 370 of these stores load the malware via https://naturalfreshmall[.]com/image/pixel[.]js. — Sansec (@sansecio) January 25, 2022 |
| domain | pixel.js | s load the malware via https://naturalfreshmall[.]com/image/pixel[.]js. — Sansec (@sansecio) January 25, 2022 |
Full article221 words · extracted from therecord.media · click to collapse
Adobe has released an emergency security update on Sunday to address a zero-day vulnerability in the Magento and Adobe Commerce platforms that was actively abused in the wild by attackers. The zero-day, tracked as CVE-2022-24086, was described as a pre-authentication remote code execution issue. Adobe said the root cause of the bug was improper input validation. Versions 2.3.7-p2 and earlier and 2.4.3-p1 and earlier of the Adobe open-source CMS and the Adobe Commerce cloud e-commerce platform are considered vulnerable to attacks and should be updated right away. In a separate Magento security bulletin, Adobe described the attacks as "very limited." E-commerce sites are some of the most valuable targets on the internet today, as once they are compromised, they can be infected with malware that steals buyers' payment card data. These types of attacks, known as web skimmers or Magecart attacks, have been taking place since 2016, and they don't appear to be stopping any time soon. Just last week, e-commerce security firm SanSec reported about a campaign that infected more than 500 Magento 1.x stores. More than 350 ecommerce stores infected with malware in a single day. Today our global crawler discovered 374 ecommerce stores infected with the same strain of malware. 370 of these stores load the malware via https://naturalfreshmall[.]com/image/pixel[.]js.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/adobe-patches-magento-cms-zero-day