WSO2와 Adobe Commerce의 취약점이 CISA KEV에 추가되었습니다.
CISA는 WSO2와 Adobe Commerce, 및 Magento에서 발생한 두 가지 주요 보안 취약점을 악용 증거에 기반하여 KEV 목록에 추가했습니다. 이 취약점 중 하나는 WSO2 API Control Plane에서 발생하는 경로 탐색 취약점으로, CVSS 점수는 9.8입니다. 이는 심각한 보안 위협을 암시하며 사용자에게 주의가 필요합니다.
Critical vulnerabilities in WSO2 and Adobe Commerce added to CISA's KEV.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical security vulnerabilities affecting WSO2 and Adobe Commerce, including Magento, to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation. One of the vulnerabilities is a path traversal issue in WSO2 API Control Plane, with a CVSS score of 9.8. This indicates a serious security threat and highlights the need for user awareness.