{"cvss":9.8,"datePublished":"2024-07-17","dateUpdated":"2024-07-17","description":"Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution.","dueDate":"2024-08-07","id":"CVE-2024-34102","kev_catalogs":["cisa"],"knownRansomwareCampaignUse":"Unknown","notes":"https://helpx.adobe.com/security/products/magento/apsb24-40.html;  https://nvd.nist.gov/vuln/detail/CVE-2024-34102","product":"Commerce and Magento Open Source","requiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","severity":"CRITICAL","source":"cisa_known_exploited","title":"Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability","vendor":"Adobe"}