CVE-2019-7896: High severity centos libgcc vulnerability
A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with administrator privileges to layouts can execute arbitrary code through a combination of product import, crafted csv file and XML layout update.
Other sources
PRODSECBUG-2298: Arbitrary code execution through product imports and design layout update
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7896?
CVE-2019-7896 is rated as a critical vulnerability due to the potential for remote code execution.
How do I fix CVE-2019-7896?
To remediate CVE-2019-7896, update your Magento installation to version 2.1.18, 2.2.9, or 2.3.2 or later.
Who is affected by CVE-2019-7896?
CVE-2019-7896 affects Magento 2.1 versions prior to 2.1.18, 2.2 versions prior to 2.2.9, and 2.3 versions prior to 2.3.2.
What types of attacks can exploit CVE-2019-7896?
CVE-2019-7896 can be exploited by authenticated users with administrator privileges through a crafted CSV file.
Is there a workaround for CVE-2019-7896?
There is no official workaround for CVE-2019-7896; updating to the patched versions is the recommended course of action.