Hello everyone,
I just got a message in the magento admin about applying a security patch about CVE-2024-34102.
As I have read in the documentation here, most of the text refers to the Commerce edition and not the Open Source.
So, my questions are:
1. Do I have to apply the patch to my open source installation too?
2. If yes, which patch do I apply? My Magento vesrion is 2.4.2 and I see patches only for 2.4.4 and above.
I'm a bit confused here that's why I'm asking for some guidance.
Thank you in advance.
You don't see a patch for 2.4.2 because you should have updated your Magento 2.4.2 to the latest version long time ago. They don't even release the security patches for a version that old. For your specific version, they stopped releasing security updates back in November 28, 2022.
So in your case, the process should be to update the version of Magento to the latest version first.
Hello @dimitrahec6cb8
Yes, if you're using Magento Open Source and a security patch has been released, you should apply the patch to your installation as well.
Magento 2.4.2 is no longer the most up-to-date version, so many new patches (especially for security) may not target 2.4.2 directly. If no specific patch is available for your version, consider upgrading to a later version of Magento, such as 2.4.4 or 2.4.5, where these patches will be available and compatible.
Hope it helps !
If you find our reply helpful, please give us kudos.
A Leading Magento Development Agency That Delivers Powerful Results, Innovation, and Secure Digital Transformation.
WebDesk Solution Support Team
Get a Free Quote | | Adobe Commerce Partner | Hire Us | Call Us 877.536.3789
Thank You,
WebDesk Solution Support Team
Get a Free Quote | Email | Adobe Commerce Partner | Hire Us | Call Us 877.536.3789
Location: 150 King St. W. Toronto, ON M5H 1J9