PT-2017-13081 · Fastly+1 · Fastly Cdn Module+1

Published

2017-09-14

·

Updated

2022-05-17

·

CVE-2017-13761

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Fastly CDN module for Magento2 versions prior to 1.2.26
Description The issue allows remote authenticated users to obtain sensitive information from authenticated sessions. This is possible when the Fastly CDN module is used with a third-party authentication plugin, and it involves vectors related to the caching of redirect responses.
Recommendations For Fastly CDN module for Magento2 versions prior to 1.2.26, update to version 1.2.26 or later to resolve the issue. As a temporary workaround, consider disabling the use of third-party authentication plugins with the Fastly CDN module until the update is applied.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-13761
GHSA-VPQ9-C67Q-23FQ

Affected Products

Fastly Cdn Module
Magento2