magento/product-enterprise-edition is vulnerable to Incorrect Authorization
90
Critical Risk
Affected versions of this package are vulnerable to several security risks: successful exploitation of known flaws can result in security feature bypass, privilege escalation, arbitrary file system read, and application denial-of-service (DoS) in Adobe Commerce and Magento Open Source platforms. The issues include improper input validation (CWE-20), CSRF (CWE-352), incorrect authorization (CWE-863), stored cross-site scripting (CWE-79), TOCTOU race conditions (CWE-367), and path traversal (CWE-22).
You are affected if you are using a version that falls within the vulnerable range.
magento/product-enterprise-edition is vulnerable to Incorrect Authorization in versions 2.4.8 - 2.4.8-p1, 2.4.7 - 2.4.7-p6, 2.4.6 - 2.4.6-p11, 2.4.5 - 2.4.5-p13 and 2.0.0 - 2.4.4-p14.
Upgrade magento/product-enterprise-edition to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant