CVE-2019-7951: Infoleak
An information leakage vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. A SOAP web service endpoint does not properly enforce parameters related to access control. This could be abused to leak customer information via crafted SOAP requests.
Other sources
PRODSECBUG-2430: Security bypass via crafted SOAP requests
Affected Software
Event History
Frequently Asked Questions
What versions are affected by CVE-2019-7951?
CVE-2019-7951 affects Magento 2.1 prior to 2.1.18, 2.2 prior to 2.2.9, and 2.3 prior to 2.3.2.
What is the severity of CVE-2019-7951?
The severity of CVE-2019-7951 is high due to the potential for customer information leakage.
How do I fix CVE-2019-7951?
You can fix CVE-2019-7951 by updating to Magento 2.1.18, 2.2.9, or 2.3.2.
What type of vulnerability is CVE-2019-7951?
CVE-2019-7951 is an information leakage vulnerability related to improper access control in SOAP web services.
Can CVE-2019-7951 be exploited by remote attackers?
Yes, CVE-2019-7951 can be exploited by remote attackers through crafted SOAP requests.