CVE-2019-8110: High severity centos libgcc vulnerability
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can leverage email templates hierarchy to manipulate the interceptor class in a way that allows an attacker to execute arbitrary code.
Other sources
PRODSECBUG-2470: Remote Code Execution in email templates
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8110?
CVE-2019-8110 has been classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2019-8110?
To mitigate CVE-2019-8110, upgrade to Magento 2.2.10 or 2.3.3 (or higher versions) immediately.
Who is affected by CVE-2019-8110?
CVE-2019-8110 affects Magento versions 2.2 prior to 2.2.10 and 2.3 prior to 2.3.3 or 2.3.2-p1.
What does CVE-2019-8110 exploit?
CVE-2019-8110 exploits the email templates hierarchy, allowing an authenticated user to manipulate the interceptor class.
Is simple user authentication enough to prevent CVE-2019-8110?
No, simple user authentication is insufficient to prevent CVE-2019-8110 as it requires only an authenticated user to exploit the vulnerability.