CVE-2019-8122: High severity centos libgcc vulnerability
A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated user with privileges to create products can craft custom layout update and use import product functionality to enable remote code execution.
Other sources
PRODSECBUG-2446: Remote code execution via custom layout update in create product functionality
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8122?
CVE-2019-8122 is classified as a critical remote code execution vulnerability affecting specific versions of Magento.
How do I fix CVE-2019-8122?
To fix CVE-2019-8122, upgrade Magento to version 2.1.19, 2.2.10, or 2.3.3 or later.
Who is affected by CVE-2019-8122?
CVE-2019-8122 affects authenticated users with privileges to create products on Magento versions prior to the recommended fixed versions.
What can attackers achieve with CVE-2019-8122?
Attackers exploiting CVE-2019-8122 can perform remote code execution, potentially compromising the security of the Magento installation.
Is CVE-2019-8122 present in all Magento installations?
No, CVE-2019-8122 is only present in specific affected versions of Magento prior to the security updates.