Security Bypass in Magento 2 Products by Adobe
CVE-2019-8133
6.5MEDIUM
What is CVE-2019-8133?
A security bypass vulnerability in Adobe's Magento platform enables users with sitemap generation privileges to circumvent directory access restrictions. This serious flaw allows for the overwriting of key configuration files, which may ultimately lead to service disruptions and unauthorized access to sensitive areas of the application.
Affected Version(s)
Magento 2 Magento 2.2 prior to 2.2.10
Magento 2 Magento 2.3 prior to 2.3.3 or 2.3.2-p1