
Cloud Vulnerability DB
A community-led vulnerabilities database
An information disclosure vulnerability was identified in Magento versions 2.4.0 and 2.3.4 (and earlier) that affects the system when in maintenance mode. The vulnerability was assigned CVE-2020-24406 and was discovered by Ihorsv. The issue was officially recorded on August 19, 2020 (CVE Details).
The vulnerability is classified as an information disclosure issue (CWE-200) and path traversal vulnerability (CWE-22). It received a CVSS v3.1 Base Score of 3.7 (LOW) with the vector string CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N, and a CVSS v2.0 Base Score of 4.3 (MEDIUM) with the vector string (AV:N/AC:M/Au:N/C:P/I:N/A:N) (NVD Database).
The vulnerability could expose the installation path during build deployments when the system is in maintenance mode. This exposure of sensitive information could potentially assist attackers in identifying other exploitable vulnerabilities in the environment (NVD Database).
The vulnerability requires network access and has high attack complexity according to its CVSS metrics. No authentication is required to exploit the vulnerability, though it does require specific conditions to be met, namely the system being in maintenance mode (NVD Database).
Adobe has released security updates to address this vulnerability. Users of affected versions (Magento 2.4.0 and 2.3.4 or earlier) should update their installations to the latest version (Adobe Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."