PT-2019-18824 · Adobe · Magento
Published
2019-08-02
·
Updated
2022-05-24
·
CVE-2019-7915
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Magento 2.1 prior to 2.1.18
Magento 2.2 prior to 2.2.9
Magento 2.3 prior to 2.3.2
Description
A denial-of-service issue exists, allowing an unauthenticated attacker to force the Magento store's full page cache to serve a 404 page to customers under certain conditions.
Recommendations
For Magento 2.1 prior to 2.1.18, update to version 2.1.18 or later.
For Magento 2.2 prior to 2.2.9, update to version 2.2.9 or later.
For Magento 2.3 prior to 2.3.2, update to version 2.3.2 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Magento