CVE-2019-8116: High severity centos libgcc vulnerability
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can leverage a guest session id value following a successful login to gain access to customer account index page.
Other sources
PRODSECBUG-2456: Broken authentication and session managememt
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8116?
CVE-2019-8116 is classified as a critical vulnerability due to its potential to allow unauthorized access to sensitive customer information.
How do I fix CVE-2019-8116?
To fix CVE-2019-8116, you should upgrade to Magento version 2.2.10 or 2.3.3 or newer.
What versions of Magento are affected by CVE-2019-8116?
CVE-2019-8116 affects Magento versions prior to 2.2.10 and 2.3.3, including Magento 2.2.x and 2.3.0 to 2.3.2-p1.
What type of attack does CVE-2019-8116 facilitate?
CVE-2019-8116 facilitates unauthorized access to customer accounts by leveraging a guest session ID.
Is CVE-2019-8116 an authenticated or unauthenticated vulnerability?
CVE-2019-8116 is an unauthenticated vulnerability, allowing attackers to exploit it without needing valid credentials.