GHSA-rwf7-652f-76mv
Dashboard / Vulnerabilities / GHSA-rwf7-652f-76mv
GHSA-rwf7-652f-76mv
Summary: Magento 2 Community Edition vulnerable to Improper Authorization
Details: Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability within the Integrations component. This vulnerability could be abused by users with permissions to the Pages resource to delete cms pages via the REST API without authorization.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-24404, https://devdocs.magento.com/guides/v2.3/release-notes/open-source-2-3-6.html, https://experienceleague.adobe.com/docs/commerce-operations/release/notes/magento-open-source/2-4-1.html, https://github.com/magento/magento2, https://helpx.adobe.com/security/products/magento/apsb20-59.html
Affected packages
Package
Name: magento/community-edition
Purl: pkg:composer/magento/community-edition
Affected ranges
Type: ECOSYSTEM
Events:
