Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect authorization vulnerability. A user can still access resources provisioned under their old role after an administrator removes the role or disables the user's account.
References
Link | Resource |
---|---|
https://helpx.adobe.com/security/products/magento/apsb20-59.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-11-08 17:15
Updated : 2020-11-12 09:57
NVD link : CVE-2020-24401
Mitre link : CVE-2020-24401
JSON object : View
CWE
CWE-863
Incorrect Authorization
Products Affected
magento
- magento