CVE-2019-8124: Medium severity centos libgcc vulnerability
An insufficient logging and monitoring vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. Failure to track admin actions related to design configuration could lead to repudiation attacks.
Other sources
PRODSECBUG-2444: Missing logs of configuration changes related to design update
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8124?
CVE-2019-8124 is categorized as a medium severity vulnerability due to its potential for repudiation attacks.
How do I fix CVE-2019-8124?
To fix CVE-2019-8124, you need to upgrade to Magento versions 2.1.19, 2.2.10, or 2.3.3.
Which versions of Magento are affected by CVE-2019-8124?
CVE-2019-8124 affects Magento 2.1 prior to 2.1.19, 2.2 prior to 2.2.10, and 2.3 prior to 2.3.3.
What type of vulnerability is CVE-2019-8124?
CVE-2019-8124 is an insufficient logging and monitoring vulnerability.
What are the risks associated with CVE-2019-8124?
The risks associated with CVE-2019-8124 include the potential for unauthorized changes to design configurations and subsequent repudiation attacks.