CVE-2019-8093: Malicious File Upload
An arbitrary file access vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can leverage file upload controller for downloadable products to read/delete an arbitary files.
Other sources
PRODSECBUG-2485: Information Disclosure via File upload functionality
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8093?
CVE-2019-8093 has a medium severity rating and allows an authenticated user to access arbitrary files.
How do I fix CVE-2019-8093?
To fix CVE-2019-8093, upgrade to Magento versions 2.2.10 or 2.3.3 and above.
Who is affected by CVE-2019-8093?
CVE-2019-8093 affects Magento versions 2.2 prior to 2.2.10 and 2.3 prior to 2.3.2-p1.
What types of vulnerabilities are exposed in CVE-2019-8093?
CVE-2019-8093 exposes information disclosure vulnerabilities via the file upload function.
Can an unauthenticated user exploit CVE-2019-8093?
No, CVE-2019-8093 requires authentication to exploit the arbitrary file access vulnerability.