CVE-2019-8107: Medium severity centos libgcc vulnerability
An arbitrary file deletion vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with export data transfer privileges can craft a request to perform arbitrary file deletion.
Other sources
PRODSECBUG-2484: Arbitrary file deletion through export data data transfer
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8107?
CVE-2019-8107 has a medium severity rating as it allows authenticated users to perform arbitrary file deletions.
How do I fix CVE-2019-8107?
To fix CVE-2019-8107, update your Magento installation to version 2.2.10 or 2.3.3 to mitigate the vulnerability.
Who is affected by CVE-2019-8107?
CVE-2019-8107 affects Magento versions 2.2 prior to 2.2.10 and 2.3 prior to 2.3.3 or 2.3.2-p1.
What type of vulnerability is CVE-2019-8107?
CVE-2019-8107 is classified as an arbitrary file deletion vulnerability.
What can an attacker do with CVE-2019-8107?
An attacker with export data transfer privileges could craft a request to delete arbitrary files on the server.