Adobe Commerce 2.4.4-p4 is a security release that provides three security fixes that enhance your Adobe Commerce 2.4.4 or Magento Open Source 2.4.4 deployment. It provides fixes for vulnerabilities that have been identified in previous releases.
jQuery-UI library version 1.13.1 has a known security vulnerability (CVE-2022-31160) that affects multiple versions of Adobe Commerce and Magento Open Source. This library is a dependency of Adobe Commerce and Magento Open Source 2.4.4, 2.4.5, and 2.4.6. Merchants running affected deployments should apply the patch specified in the jQuery UI security vulnerability CVE-2022-31160 fix for 2.4.4, 2.4.5, and 2.4.6 releases Knowledge Base article.
Security enhancements for this release improve compliance with the latest security best practices. These improvements include 13 security fixes and platform upgrades.
This security patch includes:
This patch includes 13 security fixes. See Adobe Security Bulletin for the latest discussion of these fixed issues.
The default behavior of the
isEmailAvailable GraphQL query and (
V1/customers/isEmailAvailable) REST endpoint has changed. By default, the API now always returns
true. Merchants can enable the original behavior, which is to return
true if the email does not exist in the database and
false if it exists.
Platform upgrades for this release improve compliance with the latest security best practices.
Varnish cache 7.3 support. This release is compatible with the latest version of Varnish Cache 7.3. Compatibility remains with the 6.0.x and 7.2.x versions, but we recommended using Adobe Commerce 2.4.4-p4 only with Varnish Cache version 7.3 or version 6.0 LTS.
RabbitMQ 3.11 support. This release is compatible with the latest version of RabbitMQ 3.11. Compatibility remains with RabbitMQ 3.9, which is supported through August 2023, but we recommended using Adobe Commerce 2.4.4-p4 only with RabbitMQ 3.11.
moment.js library (v2.29.4),
jQuery UI library (v1.13.2), and
jQuery validation plugin library (v1.19.5).
For instructions on downloading and applying security patches (including patch 2.4.4-p4), see Quick start install.
For general information about security patches, see Introducing the New Security Patch Release.