CVE-2025-24430
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this race condition to alter a condition after it has been checked but before it is used, potentially bypassing rate limiting mechanisms. Exploitation of this issue does not require user interaction.
Vendor
Product
CWE
Yayın Tarihi
2025-02-11 18:15:45
Güncelleme
2025-04-16 14:25:10
Source Identifier
psirt@adobe.com
KEV Date Added
-