CVE-2019-7854: High severity centos libgcc vulnerability
An insecure direct object reference (IDOR) vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can lead to unauthorized disclosure of company credit history details.
Other sources
PRODSECBUG-2132: Insecure Direct Object Reference (IDOR) vulnerability can expose sensitive company details
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7854?
CVE-2019-7854 is considered a medium severity vulnerability due to its potential for unauthorized disclosure of sensitive information.
How do I fix CVE-2019-7854?
To fix CVE-2019-7854, upgrade to Magento version 2.1.18, 2.2.9, or 2.3.2 or later.
What is the impact of CVE-2019-7854?
The impact of CVE-2019-7854 is the unauthorized disclosure of company credit history details, which could lead to data breaches.
Which Magento versions are affected by CVE-2019-7854?
Magento versions 2.1 prior to 2.1.18, 2.2 prior to 2.2.9, and 2.3 prior to 2.3.2 are affected by CVE-2019-7854.
Is any action required if I am using the patched versions of Magento?
If you are using Magento versions 2.1.18, 2.2.9, or 2.3.2 or later, no action is required as the vulnerability is patched.