PT-2020-6325 · Adobe · Magento

Published

2020-04-28

·

Updated

2024-03-06

·

CVE-2020-9580

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Magento versions 2.3.4 and earlier Magento versions 2.2.11 and earlier Magento versions 1.14.4.4 and earlier Magento versions 1.9.4.4 and earlier
Description The issue is related to incorrect code generation management in the Magento platform, which could allow a remote attacker to execute arbitrary code. Successful exploitation of this security mitigation bypass could lead to arbitrary code execution.
Recommendations For Magento versions 2.3.4 and earlier, update to a version later than 2.3.4 to resolve the issue. For Magento versions 2.2.11 and earlier, update to a version later than 2.2.11 to resolve the issue. For Magento versions 1.14.4.4 and earlier, update to a version later than 1.14.4.4 to resolve the issue. For Magento versions 1.9.4.4 and earlier, update to a version later than 1.9.4.4 to resolve the issue.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2021-04186
BIT-MAGENTO-2020-9580
CVE-2020-9580
GHSA-J2JP-58GV-G2PG

Affected Products

Magento