PT-2020-5104 · Adobe · Magento

Published

2020-07-28

·

Updated

2024-03-06

·

CVE-2020-9690

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Magento versions 2.3.5-p1 and earlier
Description The issue is related to an observable timing discrepancy, which could lead to a signature verification bypass. This vulnerability is associated with information disclosure through a discrepancy. Successful exploitation could allow a remote attacker to access protected information.
Recommendations For Magento versions 2.3.5-p1 and earlier, update to a version that addresses the observable timing discrepancy vulnerability to prevent signature verification bypass and information disclosure. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Side Channel Attack

Weakness Enumeration

Related Identifiers

BDU:2020-05700
BIT-MAGENTO-2020-9690
CVE-2020-9690
GHSA-XGP9-J48H-JJF9

Affected Products

Magento