CVE-2019-7915: High severity centos libgcc vulnerability
A denial-of-service vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Under certain conditions, an unauthenticated attacker could force the Magento store's full page cache to serve a 404 page to customers.
Other sources
PRODSECBUG-2325: Denial-of-service by forcing a store to respond with a 404 error
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7915?
CVE-2019-7915 has a severity rating that may classify it as a denial-of-service vulnerability affecting affected Magento versions.
How do I fix CVE-2019-7915?
To resolve CVE-2019-7915, upgrade Magento to version 2.1.18, 2.2.9, or 2.3.2 or later.
Which Magento versions are vulnerable to CVE-2019-7915?
Magento versions 2.1 prior to 2.1.18, 2.2 prior to 2.2.9, and 2.3 prior to 2.3.2 are vulnerable to CVE-2019-7915.
Can CVE-2019-7915 be exploited by authenticated users?
CVE-2019-7915 can be exploited by unauthenticated attackers, allowing them to affect the Magento store's cache.
What symptoms indicate an exploitation of CVE-2019-7915?
An indication of CVE-2019-7915 exploitation is the Magento store returning a 404 error page to customers.