CVE-2015-3457: Medium severity centos libgcc vulnerability
Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allow remote attackers to bypass authentication via the forwarded parameter.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3457?
CVE-2015-3457 has a critical severity rating as it allows remote attackers to bypass authentication.
How do I fix CVE-2015-3457?
To fix CVE-2015-3457, update your Magento installation to versions 1.9.1.1 or higher for Community Edition and 1.14.1.1 or higher for Enterprise Edition.
What versions are affected by CVE-2015-3457?
CVE-2015-3457 affects Magento Community Edition 1.9.1.0 and Enterprise Edition 1.14.1.0.
Is CVE-2015-3457 a remote vulnerability?
Yes, CVE-2015-3457 is a remote vulnerability that can be exploited by attackers to gain unauthorized access.
How can CVE-2015-3457 affect my Magento store?
CVE-2015-3457 can allow attackers to bypass authentication, potentially compromising sensitive data and administrative control of your Magento store.