RULE(RULE ID:338230)

Rule General Information
Release Date: 2024-07-09
Rule Name: Adobe Magento E-commerce Platform estimate-shipping-methods XXE Vulnerability (CVE-2024-34102)
Severity:
CVE ID:
Rule Protection Details
Description: Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference: AdobeSecurityBulletins:apsb24-40
Solutions
Refer to the announcement or patch by the vendor: https://helpx.adobe.com/security/products/magento/apsb24-40.html