First published: Tue Jun 25 2019(Updated: )
An insecure direct object reference (IDOR) vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can lead to unauthorized disclosure of company credit history details.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/magento/product-community-edition | >=2.1<2.1.18>=2.2<2.2.9>=2.3<2.3.2 | |
composer/magento/community-edition | >=2.3.0<2.3.2 | 2.3.2 |
composer/magento/community-edition | >=2.2.0<2.2.9 | 2.2.9 |
composer/magento/community-edition | >=2.1.0<2.1.18 | 2.1.18 |
CentOS Libgcc | >=2.1.0<2.1.18 | |
CentOS Libgcc | >=2.2.0<2.2.9 | |
CentOS Libgcc | >=2.3.0<2.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7854 is considered a medium severity vulnerability due to its potential for unauthorized disclosure of sensitive information.
To fix CVE-2019-7854, upgrade to Magento version 2.1.18, 2.2.9, or 2.3.2 or later.
The impact of CVE-2019-7854 is the unauthorized disclosure of company credit history details, which could lead to data breaches.
Magento versions 2.1 prior to 2.1.18, 2.2 prior to 2.2.9, and 2.3 prior to 2.3.2 are affected by CVE-2019-7854.
If you are using Magento versions 2.1.18, 2.2.9, or 2.3.2 or later, no action is required as the vulnerability is patched.