« Volver al listado

CVE-2020-24403

Estado: ModificadaBaja (2.7)—

Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect user permissions vulnerability within the Inventory component. This vulnerability could be abused by authenticated users with Inventory and Source permissions to make unauthorized changes to inventory source data via the REST API.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-24403",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@adobe.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 2.7,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 2.7,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@adobe.com",
      "affectedData": [
        {
          "vendor": "Adobe",
          "product": "Magento Commerce",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "2.4.0"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "2.3.5p1"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "None"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-11-09T01:15:12.620",
  "references": [
    {
      "url": "https://helpx.adobe.com/security/products/magento/apsb20-59.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@adobe.com"
    },
    {
      "url": "https://helpx.adobe.com/security/products/magento/apsb20-59.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@adobe.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-285"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect user permissions vulnerability within the Inventory component. This vulnerability could be abused by authenticated users with Inventory and Source permissions to make unauthorized changes to inventory source data via the REST API."
    },
    {
      "lang": "es",
      "value": "Magento versiones 2.4.0 y 2.3.5p1 (y anteriores) están afectadas por una vulnerabilidad de permisos de usuario inapropiados dentro del componente Inventory. Esta vulnerabilidad podría ser abusada por parte de usuarios autentificados con permisos a Inventory y Source para realizar cambios no autorizados en los datos de las fuentes de inventario por medio de la API REST"
    }
  ],
  "lastModified": "2026-06-17T03:05:30.340",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E0A4B080-331A-45E2-85A7-ED717F6EAA53",
              "versionEndExcluding": "2.3.5"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "64E6568D-2E8F-4E7F-9DEE-96B64D8AF769",
              "versionEndExcluding": "2.3.5"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:2.3.5:-:*:*:commerce:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5C6FC988-E98F-45F1-9FED-426BD70B9EED"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:2.3.5:-:*:*:open_source:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8FA0AF98-C822-4419-B4ED-E74AB5A740D1"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:2.3.5:p1:*:*:commerce:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "781C23A0-98B7-4893-97E4-AADA97AF2DF1"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:2.3.5:p1:*:*:open_source:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F43338E3-3C5B-4923-87A1-057AD501BD28"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:2.4.0:*:*:*:commerce:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8B564171-2253-412F-B936-8FEA1074BBBE"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:2.4.0:*:*:*:open_source:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "446F9B89-3455-46F4-A7B0-CCA7857E0FC4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@adobe.com"
}