Adobe Magento Products Remote Code Execution Vulnerability
Last Update Date:
3 Feb 2020 10:46
Release Date:
3 Feb 2020
5227
Views
RISK: Medium Risk
TYPE: Servers - Internet App Servers
Multiple vulnerabilities were identified in Adobe Magento Products, a remote attacker could exploit this vulnerability to trigger remote code execution on the targeted system.
Impact
- Remote Code Execution
System / Technologies affected
- Magento Commerce 2.2.10 and earlier versions
- Magento Commerce 2.3.3 and earlier versions
- Magento Open Source 2.2.10 and earlier versions
- Magento Open Source 2.3.3 and earlier versions
- Magento Enterprise Edition 1.14.4.3 and earlier versions
- Magento Community Edition 1.9.4.3 and earlier versions
Solutions
Before installation of the software, please visit the vendor web-site for more details.
- Apply fixes issued by the vendor:
Magento Commerce 2.2.11
Magento Commerce 2.3.4
Magento Open Source 2.2.11
Magento Open Source 2.3.4
Magento Open Source 1.14.4.4
Magento Community Edition 1.9.4.4
For detail, please refer to the link below:
https://helpx.adobe.com/security/products/magento/apsb20-02.html
Vulnerability Identifier
Source
Related Link
Share with