PT-2020-6327 · Adobe · Magento

Published

2020-04-28

·

Updated

2024-03-06

·

CVE-2020-9585

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Magento versions 2.3.4 and earlier Magento versions 2.2.11 and earlier Magento versions 1.14.4.4 and earlier Magento versions 1.9.4.4 and earlier
Description The issue is related to incorrect code generation management in the Magento Commerce platform. It may allow a remote attacker to execute arbitrary code.
Recommendations For versions 2.3.4 and earlier, update to a version that includes the security mitigation. For versions 2.2.11 and earlier, update to a version that includes the security mitigation. For versions 1.14.4.4 and earlier, update to a version that includes the security mitigation. For versions 1.9.4.4 and earlier, update to a version that includes the security mitigation.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2021-04188
BIT-MAGENTO-2020-9585
CVE-2020-9585
GHSA-55GV-HFG3-HWJQ

Affected Products

Magento