Insecure Authentication and Session Management in Magento by Adobe
CVE-2019-8149

9.8CRITICAL

Key Information:

Vendor
Adobe
Status
Vendor
CVE Published:
6 November 2019

Summary

An insecure authentication and session management vulnerability exists in specific versions of Magento, allowing unauthenticated users to append arbitrary session IDs. This flaw fails to invalidate session IDs after successful authentication, potentially granting unauthorized access to sensitive functionalities within the application.

Affected Version(s)

Magento 2 Magento 2.2 prior to 2.2.10

Magento 2 Magento 2.3 prior to 2.3.3 or 2.3.2-p1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.