CVE-2019-8090: Medium severity centos libgcc vulnerability
Published Oct 8, 2019
·Updated
An arbitrary file deletion vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated users can manipulate the design layout update feature.
Other sources
PRODSECBUG-2494: Arbitrary file deletion through design layout update
Affected Software
11 affected componentsFixes available
composer/magento/product-community-edition>=2.2, <2.2.10, >=2.3, <2.3.2-p2
composer/magento/community-edition>=2.3.0<2.3.3
2.3.3
composer/magento/community-edition>=2.2.0<2.2.10
2.2.10
Magento Magento>=2.1.0<2.1.19
Magento Magento>=2.1.0<2.1.19
Magento Magento>=2.2.0<2.2.10
Magento Magento>=2.2.0<2.2.10
Magento Magento>=2.3.0<2.3.2
Magento Magento>=2.3.0<2.3.2
Magento Magento=2.3.2
Magento Magento=2.3.2
Remediation
Event History
Oct 8, 2019
Advisory Published
12:00 AM
Nov 5, 2019
CVE Published
via MITRE·09:53 PM
Data Sourced
via MITRE·09:53 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-8090?
CVE-2019-8090 has a medium severity rating as it allows authenticated users to delete arbitrary files.
2
How do I fix CVE-2019-8090?
To fix CVE-2019-8090, upgrade to Magento version 2.3.3, 2.2.10, or 2.1.19 or later.
3
Who is affected by CVE-2019-8090?
CVE-2019-8090 affects Magento 2.1 prior to 2.1.19, 2.2 prior to 2.2.10, and 2.3 prior to 2.3.3.
4
What type of vulnerability is CVE-2019-8090?
CVE-2019-8090 is classified as an arbitrary file deletion vulnerability.
5
Can unprivileged users exploit CVE-2019-8090?
No, CVE-2019-8090 can only be exploited by authenticated users with access to the design layout update feature.