CVE-2019-12440: Critical severity sitecore vulnerability
The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious commands and code via the Sitecore Rocks Hard Rocks Service.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-12440?
CVE-2019-12440 is a vulnerability in the Sitecore Rocks plugin before version 2.1.149 for Sitecore that allows an unauthenticated threat actor to inject malicious commands and code.
How severe is CVE-2019-12440?
CVE-2019-12440 has a severity rating of 9.8 (critical).
What software versions are affected by CVE-2019-12440?
CVE-2019-12440 affects Sitecore Rocks plugin versions up to (but not including) 2.1.149 for Sitecore.
How can the vulnerability be fixed?
To fix CVE-2019-12440, update the Sitecore Rocks plugin to version 2.1.149 or newer.
Where can I find more information about CVE-2019-12440?
You can find more information about CVE-2019-12440 at the following references: [GitHub Comparison](https://github.com/Sitecore/Sitecore.Rocks/compare/be79dcc...bd9ba6a), [GitHub Releases](https://github.com/Sitecore/Sitecore.Rocks/releases/tag/2.1.149), [Sitecore Knowledge Base Article](https://kb.sitecore.net/articles/842902).