Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-427g-2r83-3ccm

Опубликовано: 12 нояб. 2019
Источник: github
Github: Прошло ревью
CVSS3: 4.9

Описание

Information disclosure through processing of external XML entities

An XML entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can craft document type definition for an XML representing XML layout. The crafted document type definition and XML layout allow processing of external entities which can lead to information disclosure.

As per the Magento Release 2.3.3, if you have already implemented the pre-release version of this patch (2.3.2-p1), it is highly recommended to promptly upgrade to 2.3.2-p2.

Пакеты

Наименование

magento/community-edition

composer
Затронутые версииВерсия исправления

>= 2.2, < 2.2.10

2.2.10

Наименование

magento/community-edition

composer
Затронутые версииВерсия исправления

>= 2.3, < 2.3.2-p2

2.3.2-p2

EPSS

Процентиль: 29%
0.00108
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-611
CWE-776

Связанные уязвимости

CVSS3: 4.9
nvd
больше 6 лет назад

An XML entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can craft document type definition for an XML representing XML layout. The crafted document type definition and XML layout allow processing of external entities which can lead to information disclosure.

EPSS

Процентиль: 29%
0.00108
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-611
CWE-776