CVE-2017-13761: Infoleak
The Fastly CDN module before 1.2.26 for Magento2, when used with a third-party authentication plugin, might allow remote authenticated users to obtain sensitive information from authenticated sessions via vectors involving caching of redirect responses.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-13761?
CVE-2017-13761 is considered a medium severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2017-13761?
To fix CVE-2017-13761, upgrade the Fastly CDN module to version 1.2.26 or later.
Who is affected by CVE-2017-13761?
Magento 2 users employing the Fastly CDN module with third-party authentication plugins are affected by CVE-2017-13761.
What type of attack does CVE-2017-13761 facilitate?
CVE-2017-13761 facilitates a remote authenticated user attack that can lead to the leakage of sensitive session information.
What is the potential impact of CVE-2017-13761?
The potential impact of CVE-2017-13761 includes unauthorized access to sensitive user data through cached response vectors.