PT-2019-18934 · Adobe · Magento

Publicado

2019-11-06

·

Atualizado

2022-05-24

·

CVE-2019-8158

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Magento 2.2 versions 2.2.0 through 2.2.9 Magento 2.3 versions 2.3.0 through 2.3.2
Description An XPath entity injection issue exists, allowing an attacker to craft a GET request to the page cache block rendering module. This request gets passed to the XML data processing engine without validation, enabling limited access to underlying XML data.
Recommendations For Magento 2.2 versions 2.2.0 through 2.2.9, update to version 2.2.10 or later. For Magento 2.3 versions 2.3.0 through 2.3.2, update to version 2.3.3 or 2.3.2-p2 if you have already implemented the pre-release version of this patch (2.3.2-p1).

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-8158
GHSA-8P5C-F836-M4H7

Produtos afetados

Magento