CVE-2025-24430

LOW

Adobe Commerce < 2.4.4 - TOCTOU Race Condition

Title source: rule
STIX 2.1

Description

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this race condition to alter a condition after it has been checked but before it is used, potentially bypassing rate limiting mechanisms. Exploitation of this issue does not require user interaction.

Scores

CVSS v3 3.7
EPSS 0.0010
EPSS Percentile 27.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-367
Status published
Products (10)
adobe/commerce 2.4.4 (12 CPE variants)
adobe/commerce 2.4.5 (11 CPE variants)
adobe/commerce 2.4.6 (9 CPE variants)
adobe/commerce 2.4.7 (4 CPE variants)
adobe/commerce 2.4.8 beta1
adobe/commerce < 2.4.4
adobe/commerce_b2b 1.3.3 (3 CPE variants)
adobe/commerce_b2b 1.3.4 (3 CPE variants)
adobe/commerce_b2b 1.3.5 (3 CPE variants)
adobe/commerce_b2b 1.4.2 (3 CPE variants)
Published Feb 11, 2025
Tracked Since Feb 18, 2026