VYPR
High severity8.8NVD Advisory· Published Oct 20, 2022· Updated Jun 17, 2026

CVE-2022-42344

CVE-2022-42344

Description

Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Incorrect Authorization vulnerability. An authenticated attacker can exploit this vulnerability to achieve information exposure and privilege escalation.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
magento/community-editionPackagist
< 2.3.7-p42.3.7-p4
magento/community-editionPackagist
>= 2.4.0, < 2.4.3-p32.4.3-p3
magento/community-editionPackagist
>= 2.4.4, < 2.4.52.4.5

Affected products

21
  • Adobe Inc./Commerce10 versions
    cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*:*+ 9 more
    • cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*:*range: <2.3.7
    • cpe:2.3:a:adobe:commerce:2.3.7:-:*:*:*:*:*:*
    • cpe:2.3:a:adobe:commerce:2.3.7:p1:*:*:*:*:*:*
    • cpe:2.3:a:adobe:commerce:2.3.7:p2:*:*:*:*:*:*
    • cpe:2.3:a:adobe:commerce:2.3.7:p3:*:*:*:*:*:*
    • cpe:2.3:a:adobe:commerce:2.4.3:-:*:*:*:*:*:*
    • cpe:2.3:a:adobe:commerce:2.4.3:p1:*:*:*:*:*:*
    • cpe:2.3:a:adobe:commerce:2.4.3:p2:*:*:*:*:*:*
    • cpe:2.3:a:adobe:commerce:2.4.4:-:*:*:*:*:*:*
    • (no CPE)range: 0
  • Magento/Magento9 versions
    cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*+ 8 more
    • cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*range: <2.3.7
    • cpe:2.3:a:magento:magento:2.3.7:-:*:*:open_source:*:*:*
    • cpe:2.3:a:magento:magento:2.3.7:p1:*:*:open_source:*:*:*
    • cpe:2.3:a:magento:magento:2.3.7:p2:*:*:open_source:*:*:*
    • cpe:2.3:a:magento:magento:2.3.7:p3:*:*:open_source:*:*:*
    • cpe:2.3:a:magento:magento:2.4.3:-:*:*:open_source:*:*:*
    • cpe:2.3:a:magento:magento:2.4.3:p1:*:*:open_source:*:*:*
    • cpe:2.3:a:magento:magento:2.4.3:p2:*:*:open_source:*:*:*
    • cpe:2.3:a:magento:magento:2.4.4:-:*:*:open_source:*:*:*
  • osv-coords2 versions
    < 2.3.7+ 1 more
    • (no CPE)range: < 2.3.7
    • (no CPE)range: < 2.3.7-p4

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.