First published: Wed May 29 2019(Updated: )
The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious commands and code via the Sitecore Rocks Hard Rocks Service.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sitecore | <2.1.149 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12440 is a vulnerability in the Sitecore Rocks plugin before version 2.1.149 for Sitecore that allows an unauthenticated threat actor to inject malicious commands and code.
CVE-2019-12440 has a severity rating of 9.8 (critical).
CVE-2019-12440 affects Sitecore Rocks plugin versions up to (but not including) 2.1.149 for Sitecore.
To fix CVE-2019-12440, update the Sitecore Rocks plugin to version 2.1.149 or newer.
You can find more information about CVE-2019-12440 at the following references: [GitHub Comparison](https://github.com/Sitecore/Sitecore.Rocks/compare/be79dcc...bd9ba6a), [GitHub Releases](https://github.com/Sitecore/Sitecore.Rocks/releases/tag/2.1.149), [Sitecore Knowledge Base Article](https://kb.sitecore.net/articles/842902).