Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-crf2-xm6x-46p6

Опубликовано: 19 авг. 2020
Источник: github
Github: Прошло ревью
CVSS3: 8

Описание

Observable Timing Discrepancy in OpenMage LTS

Impact

This vulnerability allows to circumvent the formkey protection in the Admin Interface and increases the attack surface for Cross Site Request Forgery attacks

Patches

The latest OpenMage Versions up from 19.4.6 and 20.0.2 have this Issue solved

References

Related to Adobes CVE-2020-9690 ( https://helpx.adobe.com/security/products/magento/apsb20-47.html ) fixed in Magento2 https://github.com/magento/magento2/commit/52d72b8010c9cecb5b8e3d98ec5edc1ddcc65fb4 as part of 2.4.0/2.3.5-p2

Пакеты

Наименование

openmage/magento-lts

composer
Затронутые версииВерсия исправления

< 19.4.6

19.4.6

Наименование

openmage/magento-lts

composer
Затронутые версииВерсия исправления

>= 20.0.0, < 20.0.2

20.0.2

EPSS

Процентиль: 25%
0.00088
Низкий

8 High

CVSS3

Дефекты

CWE-203
CWE-352

Связанные уязвимости

CVSS3: 8
nvd
больше 5 лет назад

OpenMage LTS before versions 19.4.6 and 20.0.2 allows attackers to circumvent the `fromkey protection` in the Admin Interface and increases the attack surface for Cross Site Request Forgery attacks. This issue is related to Adobe's CVE-2020-9690. It is patched in versions 19.4.6 and 20.0.2.

EPSS

Процентиль: 25%
0.00088
Низкий

8 High

CVSS3

Дефекты

CWE-203
CWE-352