High severity8.8NVD Advisory· Published Oct 20, 2022· Updated Jun 17, 2026
CVE-2022-42344
CVE-2022-42344
Description
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Incorrect Authorization vulnerability. An authenticated attacker can exploit this vulnerability to achieve information exposure and privilege escalation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
magento/community-editionPackagist | < 2.3.7-p4 | 2.3.7-p4 |
magento/community-editionPackagist | >= 2.4.0, < 2.4.3-p3 | 2.4.3-p3 |
magento/community-editionPackagist | >= 2.4.4, < 2.4.5 | 2.4.5 |
Affected products
21cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*:*+ 9 more
- cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*:*range: <2.3.7
- cpe:2.3:a:adobe:commerce:2.3.7:-:*:*:*:*:*:*
- cpe:2.3:a:adobe:commerce:2.3.7:p1:*:*:*:*:*:*
- cpe:2.3:a:adobe:commerce:2.3.7:p2:*:*:*:*:*:*
- cpe:2.3:a:adobe:commerce:2.3.7:p3:*:*:*:*:*:*
- cpe:2.3:a:adobe:commerce:2.4.3:-:*:*:*:*:*:*
- cpe:2.3:a:adobe:commerce:2.4.3:p1:*:*:*:*:*:*
- cpe:2.3:a:adobe:commerce:2.4.3:p2:*:*:*:*:*:*
- cpe:2.3:a:adobe:commerce:2.4.4:-:*:*:*:*:*:*
- (no CPE)range: 0
cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*+ 8 more
- cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*range: <2.3.7
- cpe:2.3:a:magento:magento:2.3.7:-:*:*:open_source:*:*:*
- cpe:2.3:a:magento:magento:2.3.7:p1:*:*:open_source:*:*:*
- cpe:2.3:a:magento:magento:2.3.7:p2:*:*:open_source:*:*:*
- cpe:2.3:a:magento:magento:2.3.7:p3:*:*:open_source:*:*:*
- cpe:2.3:a:magento:magento:2.4.3:-:*:*:open_source:*:*:*
- cpe:2.3:a:magento:magento:2.4.3:p1:*:*:open_source:*:*:*
- cpe:2.3:a:magento:magento:2.4.3:p2:*:*:open_source:*:*:*
- cpe:2.3:a:magento:magento:2.4.4:-:*:*:open_source:*:*:*
- osv-coords2 versions
< 2.3.7+ 1 more
- (no CPE)range: < 2.3.7
- (no CPE)range: < 2.3.7-p4
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-297f-r9w7-w492ghsaADVISORY
- helpx.adobe.com/security/products/magento/apsb22-38.htmlnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-42344ghsaADVISORY
News mentions
0No linked articles in our index yet.