First published: Tue Jun 25 2019(Updated: )
PRODSECBUG-2300: Information about disabled products can be leaked due to inadequate validation checks
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/magento/product-community-edition | >=2.1<2.1.18>=2.2<2.2.9>=2.3<2.3.2 | |
composer/magento/magento1ee | >=1<1.14.4.2 | |
composer/magento/magento1ce | >=1<1.9.4.2 | |
composer/magento/community-edition | >=2.3<2.3.2 | 2.3.2 |
composer/magento/community-edition | >=2.2<2.2.9 | 2.2.9 |
composer/magento/community-edition | >=2.1<2.1.18 | 2.1.18 |
Magento | <1.9.4.2 | |
Magento | <1.14.4.2 | |
Magento | >=2.1.0<2.1.18 | |
Magento | >=2.2.0<2.2.9 | |
Magento | >=2.3.0<2.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7898 is classified as a medium severity vulnerability that can result in information leakage regarding disabled products.
To remediate CVE-2019-7898, upgrade to Magento Open Source version 2.1.18, 2.2.9, or 2.3.2, or Magento Commerce version 1.14.4.2 or later.
CVE-2019-7898 affects Magento Open Source versions prior to 2.1.18, 2.2.9, and 2.3.2, as well as Magento Commerce versions prior to 1.14.4.2.
CVE-2019-7898 is an information disclosure vulnerability that allows access to disabled product samples without proper validation.
Yes, if your Magento installation is running a version lower than 2.1.18, 2.2.9, or 2.3.2 for Open Source, or prior to 1.14.4.2 for Commerce, it is vulnerable.