PT-2017-13081 · Fastly+1 · Fastly Cdn Module+1

Publicado

2017-09-14

·

Atualizado

2022-05-17

·

CVE-2017-13761

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Fastly CDN module for Magento2 versions prior to 1.2.26
Description The issue allows remote authenticated users to obtain sensitive information from authenticated sessions. This is possible when the Fastly CDN module is used with a third-party authentication plugin, and it involves vectors related to the caching of redirect responses.
Recommendations For Fastly CDN module for Magento2 versions prior to 1.2.26, update to version 1.2.26 or later to resolve the issue. As a temporary workaround, consider disabling the use of third-party authentication plugins with the Fastly CDN module until the update is applied.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-13761
GHSA-VPQ9-C67Q-23FQ

Produtos afetados

Fastly Cdn Module
Magento2