PT-2020-6324 · Adobe · Magento

Published

2020-04-28

·

Updated

2024-03-06

·

CVE-2020-9579

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Magento versions 2.3.4 and earlier Magento versions 2.2.11 and earlier Magento versions 1.14.4.4 and earlier Magento versions 1.9.4.4 and earlier
Description The issue is related to incorrect code generation management in the Magento Commerce platform. It may allow a remote attacker to execute arbitrary code.
Recommendations For Magento versions 2.3.4 and earlier, update to a version that includes the security mitigation. For Magento versions 2.2.11 and earlier, update to a version that includes the security mitigation. For Magento versions 1.14.4.4 and earlier, update to a version that includes the security mitigation. For Magento versions 1.9.4.4 and earlier, update to a version that includes the security mitigation.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2021-04185
BIT-MAGENTO-2020-9579
CVE-2020-9579
GHSA-VRP3-WC28-QG2H

Affected Products

Magento