CVE-2019-8091: High severity centos libgcc vulnerability
Published Nov 5, 2019
·Updated
A remote code execution vulnerability exists in Magento 1 prior to 1.9.4.3 and 1.14.4.3. An authenticated admin user with privileges to access product attributes can leverage layout updates to trigger remote code execution.
Affected Software
2 affected components
Magento Magento>=1.5.0.0<1.9.4.3
Magento Magento>=1.9.0.0<1.14.4.3
Event History
Nov 5, 2019
CVE Published
via MITRE·10:08 PM
Data Sourced
via MITRE·10:08 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-8091?
CVE-2019-8091 is rated as critical due to the potential for remote code execution.
2
How do I fix CVE-2019-8091?
To fix CVE-2019-8091, upgrade your Magento installation to version 1.9.4.3 or 1.14.4.3 or later.
3
Who is affected by CVE-2019-8091?
CVE-2019-8091 affects authenticated admin users of Magento 1 versions prior to 1.9.4.3 and 1.14.4.3.
4
What types of Magento installations are impacted by CVE-2019-8091?
Both Magento Open Source and Magento Commerce installations prior to the specified versions are impacted by CVE-2019-8091.
5
Is there a workaround for CVE-2019-8091?
There is no official workaround for CVE-2019-8091; updating to a patched version is recommended.