Lucene search

K
osvGoogleOSV:GHSA-39RW-4M66-82GF
HistoryMay 24, 2022 - 5:33 p.m.

Magento incorrect user permissions vulnerability within the Inventory component

2022-05-2417:33:55
Google
osv.dev
5
magento
inventory component
user permissions
vulnerability
software
rest api

AI Score

5.4

Confidence

Low

EPSS

0.001

Percentile

38.6%

Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect user permissions vulnerability within the Inventory component. This vulnerability could be abused by authenticated users with Inventory and Source permissions to make unauthorized changes to inventory source data via the REST API.

AI Score

5.4

Confidence

Low

EPSS

0.001

Percentile

38.6%