CVE-2019-8125: High severity centos libgcc vulnerability
A remote code execution vulnerability exists in Magento 1 prior to 1.9.x and 1.14.x. An authenticated admin user can modify configuration parameters via crafted support configuration. The modification can lead to remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8125?
CVE-2019-8125 is classified as critical due to its potential for remote code execution.
How do I fix CVE-2019-8125?
To fix CVE-2019-8125, upgrade your Magento installation to version 1.9.4.4 or later for Magento Open Source, or version 1.14.4.4 or later for Magento Commerce.
Who is affected by CVE-2019-8125?
CVE-2019-8125 affects authenticated admin users of Magento 1 versions prior to 1.9.4.4 and 1.14.4.4.
What types of attacks can exploit CVE-2019-8125?
CVE-2019-8125 can be exploited to perform remote code execution through crafted modifications to configuration parameters.
Is there a workaround for CVE-2019-8125?
There is no official workaround; upgrading to a patched version is the recommended action to mitigate CVE-2019-8125.