PT-2019-18934 · Adobe · Magento
Publicado
2019-11-06
·
Atualizado
2022-05-24
·
CVE-2019-8158
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Magento 2.2 versions 2.2.0 through 2.2.9
Magento 2.3 versions 2.3.0 through 2.3.2
Description
An XPath entity injection issue exists, allowing an attacker to craft a GET request to the page cache block rendering module. This request gets passed to the XML data processing engine without validation, enabling limited access to underlying XML data.
Recommendations
For Magento 2.2 versions 2.2.0 through 2.2.9, update to version 2.2.10 or later.
For Magento 2.3 versions 2.3.0 through 2.3.2, update to version 2.3.3 or 2.3.2-p2 if you have already implemented the pre-release version of this patch (2.3.2-p1).
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Magento