CVE-2020-24401

All FrameworksMagentoCWE-863CVE-2020-24401

CVE-2020-24401

State: PUBLISHED · Published: 2020-11-09 · Updated: 2024-09-16 · Assigner: adobe
Description
Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect authorization vulnerability. A user can still access resources provisioned under their old role after an administrator removes the role or disables the user's account.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2020/24xxx/CVE-2020-24401.json