CVE-2019-8114: Malicious File Upload
A remote code execution vulnerability exists in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with admin privileges to import features can execute arbitrary code via crafted configuration archive file upload.
Other sources
PRODSECBUG-2462: Remote code execution via file upload in admin import feature
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8114?
CVE-2019-8114 is rated as a critical vulnerability due to its potential for remote code execution by unauthorized users.
How do I fix CVE-2019-8114?
To fix CVE-2019-8114, upgrade to Magento 1.9.4.3 or 1.14.4.3, Magento 2.2.10, or Magento 2.3.3 or later.
Who is affected by CVE-2019-8114?
CVE-2019-8114 affects authenticated users with admin privileges on Magento 1 and Magento 2 versions prior to their respective patch releases.
What kind of exploit is possible with CVE-2019-8114?
CVE-2019-8114 allows an attacker with admin access to execute arbitrary code through crafted configuration archive file uploads.
What versions of Magento are vulnerable to CVE-2019-8114?
Magento 1 versions prior to 1.9.4.3 and 1.14.4.3, and Magento 2 versions prior to 2.2.10 and 2.3.3 are vulnerable to CVE-2019-8114.