CVE-2019-7890: High severity centos libgcc vulnerability
An Insecure Direct Object Reference (IDOR) vulnerability exists in the order processing workflow of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can lead to unauthorized access to order details.
Other sources
PRODSECBUG-2276: Insecure Direct Object Reference (IDOR) vulnerability can expose order shipping details
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7890?
CVE-2019-7890 is considered a critical vulnerability due to its potential for unauthorized access to sensitive order details in Magento.
How do I fix CVE-2019-7890?
To fix CVE-2019-7890, upgrade Magento to version 2.1.18, 2.2.9, or 2.3.2 or later.
What versions of Magento are affected by CVE-2019-7890?
CVE-2019-7890 affects Magento 2.1 versions prior to 2.1.18, 2.2 versions prior to 2.2.9, and 2.3 versions prior to 2.3.2.
What type of vulnerability is CVE-2019-7890?
CVE-2019-7890 is classified as an Insecure Direct Object Reference (IDOR) vulnerability.
What could happen if CVE-2019-7890 is exploited?
If exploited, CVE-2019-7890 can allow attackers unauthorized access to view and potentially manipulate order details.