CVE-2019-8123: Medium severity centos libgcc vulnerability
An insufficient logging and monitoring vulnerability exists in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. The logging feature required for effective monitoring did not contain sufficent data to effectively track configuration changes.
Other sources
PRODSECBUG-2445: Insufficient logging and monitoring of configuration changes
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8123?
CVE-2019-8123 is classified as a medium severity vulnerability due to insufficient logging and monitoring.
How do I fix CVE-2019-8123?
To mitigate CVE-2019-8123, upgrade to Magento versions 1.9.4.4 or 1.14.4.4 for Magento 1, and 2.1.19, 2.2.10, or 2.3.3 for Magento 2.
What versions of Magento are affected by CVE-2019-8123?
CVE-2019-8123 affects Magento 1 versions prior to 1.9.4.3 and 1.14.4.3, as well as Magento 2.1 versions before 2.1.19, 2.2 versions before 2.2.10, and 2.3 versions before 2.3.3.
What kind of data is insufficiently logged in CVE-2019-8123?
CVE-2019-8123 involves a lack of necessary data in logging features, which hampers the effectiveness of tracking configuration changes.
Is there a patch available for CVE-2019-8123?
Yes, patches addressing CVE-2019-8123 are included in the aforementioned Magento version upgrades.