Flying Spares, provider of spare parts for vintage cars and high quality marques, displaying a Rolls-Royce from their eCommerce Shopify development from magic42

Flying Spares

International B2B Magento with 240k catalogue, Khaos Control Integration and digital marketing.
See our work
Stone Computers Case Study by magic42

Stone Computers

Adobe Magento Commerce B2C, B2B portal and PunchOut sites and bespoke loan payment solution.
See our work
Alan Paine quality clothing retailer showing their brand, as featured in their case study for their eCommerce website with magic42

Alan Paine

Multisite, B2C migration from Magento to Shopify Plus with ERP integration.
See our work
Haws Watering Cans case study after eCommerce development agency, magic42, migrated their site to Shopify

Haws Watering Cans

B2C eCommerce strategy, UX improvements, AdWords and Klaviyo email marketing management.
See our work
Alan Paine quality clothing retailer showing their brand, as featured in their case study for their eCommerce website with magic42

Alan Paine

Multi-site, B2C migration from Magento to Shopify Plus with ERP integration.
Find out more
Roger Clark Motorsport automative eCommerce client case study from magic42, showing high quality silver cars in a slick garage

Roger Clark Motorsport

B2C and B2B migration of bespoke, global automotive parts website to Shopify.
Find out more

Call Us

Speak to a Shopify expert:

0121 663 6360

Get in touch 
magic42 - eCommerce development experts born from retail success

Born from a retailer

Read the full story of how our award-winning retail business developed into magic42.
Find out more
Envision Workshop documents as an outcome from our replatforming and migration meeting for your eCommerce website

How we'll work with you

Find out what it's like to partner with us and the steps involved for your eCommerce project.
Find out more
Alex Ashman, director of magic42, in a bumper car with a huge grin on his face as he mingles with his eCommerce development team at magic42

Looking for a career with us?

Take a look at what it's like to work at magic42 and the opportunities we offer.
Find out more

Call Us

Speak to our eCommerce experts:

0121 663 6360

Get in touch 

Magento Update 11/06/24: Critical Security Update for Magento and Adobe Commerce

Author: 
Alex Ashman
Published: 
June 12, 2024
Magento and Adobe Commerce Update from eCommerce and Magento development agency, magic42

As of 11th June, Adobe has released a critical security update for Magento Open Source, Adobe Commerce and the Adobe Webhooks Plugin.

Bulletin IDDate PublishedPriority
APSB24-4011th June, 20243

The update fixes ‘critical’ issues from Adobe’s own terminology, including one with a Common Vulnerability Scoring System (CVSS) of 9.8. Measured out of 10, this score measures the severity of the issue, with the update listed as high priority - ‘Priority 3’. It’s therefore vital your site is updated as soon as possible.

Another key element of this update will be how it affects your Content Security Policy (CSP).  Following the update, Magento will now enable CSP modules on checkout pages by default. This security update, which comes as part of the recent changes to the Payment Card Industry (PCI) Data Security Standards (DSS) to PCI 4.0, backports Magento 2.4.7’s CSP restrict mode from its front-end and admin checkout pages. That means applying this update will result in the monitoring and blocking of any unauthorised scripts on payment pages.

Whilst positive from a security perspective, the Magento update could block site visitors from completing the checkout journey. To combat this, you will need to enable the CSP’s report mode to review any links being blocked. These can then be checked, with any safe URLs whitelisted to maintain full checkout functionality.

As a Magento development agency, we will be happy to do this for our Magento Open Source and Adobe Commerce clients. These will need to be done before applying the crucial Magento-based update.

Native to Magento 2.4.7, this security update is also being rolled back to previous, supported versions of Magento Open Source, Adobe Commerce and Adobe Webhooks. Here is the full list affected by the security update:

ProductVersionPlatform
Magento Open Source2.4.7 and earlier
2.4.6-p5 and earlier
2.4.5-p7 and earlier
2.4.4-p8 and earlier
All
Adobe Commerce2.4.7 and earlier
2.4.6-p5 and earlier
2.4.5-p7 and earlier
2.4.4-p8 and earlier
2.4.3-ext-7 and earlier*
2.4.2-ext-7 and earlier*
2.4.1-ext-7 and earlier*
2.4.0-ext-7 and earlier*
2.3.7-p4-ext-7 and earlier*
All
Adobe Commerce Webhooks1.2.0 to 1.4.0Manual Plugin Installation

*These versions are only applicable to those using the platform as part of Adobe’s Extended Support Program.

Need more Magento advice?

For more insight on CSPs, find out how Magento’s Content Security Policy keeps you secure. You can also find out more about the security update at the latest Adobe Security Bulletin.

Get in contact with us if you’d like to find out more about how we can keep your Magento site secure for both Magento Open Source and Adobe Commerce.

magic42 logo
magic42 is a UK-based eCommerce development agency, born from an award-winning retailer. Having grown with the industry since the year 2000, we provide our unique perspective to help clients get the best from their eCommerce platforms.
Company No. 11572347 VAT No. 310 2436 61
Adobe Solution Partners Bronze Logo, used by verified Adobe expertsShopify Partners Logo (as used by Shopify Development Partners)
© Copyright 2024 magic42 Limited - All Rights Reserved
linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram