Adobe have released a security advisory on the 14th of February 2024 in line with their regular monthly patch schedule which includes a number of updates to address six (6) medium risk vulnerabilities.
These updates address vulnerabilities which may impact services through Cross-Site Scripting, Denial of Service, Security Restriction Bypass, Remote Code Execution and Information Disclosure.
For more information please see: Adobe Security Update
This release consists of security updates for the following products:
- Adobe Commerce 2.4.6-p3 and earlier versions
- Adobe Commerce 2.4.5-p5 and earlier versions
- Adobe Commerce 2.4.4-p6 and earlier versions
- Adobe Commerce 2.4.3-ext-5 and earlier versions
- Adobe Commerce 2.4.2-ext-5 and earlier versions
- Adobe Commerce 2.4.1-ext-5 and earlier versions
- Adobe Commerce 2.4.0-ext-5 and earlier versions
- Magento Open Source 2.4.6-p3 and earlier versions
- Magento Open Source 2.4.5-p5 and earlier versions
- Magento Open Source 2.4.4-p6 and earlier versions
- Adobe Substance 3D Painter 9.1.1 and earlier versions
- Acrobat DC 23.008.20470 and earlier versions
- Acrobat Reader DC 23.008.20470 and earlier versions
- Acrobat 2020 20.005.30539 and earlier versions
- Acrobat Reader 2020 20.005.30539 and earlier versions
- Adobe FrameMaker Publishing Server Version 2022 Update 1 and earlier versions
- Adobe Audition 24.0.3 and earlier versions
- Adobe Audition 23.6.2 and earlier versions
- Adobe Substance 3D Designer 13.1.0 and earlier versions
Matsco recommends any affected systems are updated as soon as convenient.