Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted request to the server, which could then cause the server to execute arbitrary code. Exploitation of this issue does not require user interaction.
{
"cwe_ids": [
"CWE-918"
],
"severity": "MODERATE",
"github_reviewed_at": "2024-08-07T17:42:48Z",
"github_reviewed": true,
"nvd_published_at": "2024-06-13T09:15:13Z"
}