CVE-2024-34102criticalunder attackCWE-611

CVE-2024-34102: critical vulnerability in Adobe Commerce

XXE can expose crypt key and other secrets granting full admin access

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 100%
from disclosure to weapon14 days
Published on NVDJun 13
1st PoC+14d
metasploitJun 11
CISA KEV+34d
exploitation probability
100%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
41 public exploit(s)
Action required by CISAfederal deadline: 2024-08-07

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

In short

Adobe Commerce has a flaw that allows attackers to send specially crafted XML files to expose sensitive secrets like encryption keys and gain complete admin access to the store. This happens automatically without needing any user interaction.

Technical detail

An XXE (XML External Entity) vulnerability in affected Adobe Commerce versions (2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier) permits unauthenticated remote attackers to read arbitrary files and extract cryptographic keys through crafted XML payloads submitted to vulnerable endpoints. Successful exploitation grants administrative privileges and potential code execution without requiring user action or authentication.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Adobe · Adobe Commerce
public PoCs found — 41
githubgithub.com/Chocapikk/CVE-2024-34102★ 48githubgithub.com/bigb0x/CVE-2024-34102★ 31githubgithub.com/th3gokul/CVE-2024-34102★ 14githubgithub.com/jakabakos/CVE-2024-34102-CosmicSting-XXE-in-Adobe-Commerce-and-Magento★ 9githubgithub.com/bughuntar/CVE-2024-34102★ 5githubgithub.com/EQSTLab/CVE-2024-34102★ 4githubgithub.com/11whoami99/CVE-2024-34102★ 3githubgithub.com/0x0d3ad/CVE-2024-34102★ 2githubgithub.com/wubinworks/magento2-cosmic-sting-patch★ 1githubgithub.com/Phantom-IN/CVE-2024-34102★ 1githubgithub.com/nmmorette/CVE-2024-34102★ 1githubgithub.com/Kento-Sec/CVE-2024-34102★ 0githubgithub.com/russellwork2021-lgtm/cosmicsting-cve-2024-34102-exploit★ 0githubgithub.com/SamJUK/cosmicsting-validator★ 0githubgithub.com/d0rb/CVE-2024-34102★ 0githubgithub.com/cmsec423/CVE-2024-34102★ 0githubgithub.com/cmsec423/Magento-XXE-CVE-2024-34102★ 0githubgithub.com/ArturArz1/TestCVE-2024-34102★ 0githubgithub.com/unknownzerobit/poc★ 0githubgithub.com/crynomore/CVE-2024-34102★ 0githubgithub.com/dream434/CVE-2024-34102★ 0githubgithub.com/bka/magento-cve-2024-34102-exploit-cosmicstring★ 0githubgithub.com/wubinworks/magento2-encryption-key-manager-cli★ 0githubgithub.com/Koray123-debug/CVE-2024-34102★ 0vulncheckvulncheck.com/xdb/68297a933a3cunverifiedvulncheckvulncheck.com/xdb/62c07de93469unverifiedvulncheckvulncheck.com/xdb/e10072b9959aunverifiedvulncheckvulncheck.com/xdb/e16ac34e34d7unverifiedvulncheckvulncheck.com/xdb/f7ec53083d00unverifiedvulncheckvulncheck.com/xdb/56d612cb301bunverifiedvulncheckvulncheck.com/xdb/b740eaf30da0unverifiedvulncheckvulncheck.com/xdb/ff651d9ccadfunverifiedvulncheckvulncheck.com/xdb/b9a5654f364dunverifiedvulncheckvulncheck.com/xdb/2eb4d44dc79bunverifiedvulncheckvulncheck.com/xdb/18320f3f459cunverifiedvulncheckvulncheck.com/xdb/771b0f9ad8b9unverifiedvulncheckvulncheck.com/xdb/31319adbe12aunverifiedvulncheckvulncheck.com/xdb/60b0937b5f4funverifiedvulncheckvulncheck.com/xdb/dc00179a0cb9unverifiedvulncheckvulncheck.com/xdb/034f54dfbdb8unverifiedvulncheckvulncheck.com/xdb/b5758629a4e6unverified
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.