Race Condition Vulnerability in Magento Products by Adobe
CVE-2019-8232

6.6MEDIUM

Key Information:

Vendor
Adobe
Vendor
CVE Published:
6 November 2019

Summary

In the affected versions of Magento, an authenticated user with administrative privileges can exploit a race condition while using the import feature. This vulnerability allows the attacker to modify the webserver configuration files, which could lead to arbitrary code execution on the server. Proper security measures must be implemented to mitigate the risk associated with this vulnerability.

Affected Version(s)

Magento 1 & 2 Magento Open Source prior to 1.9.4.3, and Magento Commerce prior to 1.14.4.3, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.