Insecure Authentication and Session Management in Magento by Adobe
CVE-2019-8149
9.8CRITICAL
Summary
An insecure authentication and session management vulnerability exists in specific versions of Magento, allowing unauthenticated users to append arbitrary session IDs. This flaw fails to invalidate session IDs after successful authentication, potentially granting unauthorized access to sensitive functionalities within the application.
Affected Version(s)
Magento 2 Magento 2.2 prior to 2.2.10
Magento 2 Magento 2.3 prior to 2.3.3 or 2.3.2-p1
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved