CVE-2019-8141: High severity centos libgcc vulnerability
A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated user with administrative privileges (system level import) can execute arbitrary code through a Phar deserialization vulnerability in the import functionality.
Other sources
PRODSECBUG-2407: Remote code execution due to unsafe PHP archieve deserialization in the import functionality
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8141?
CVE-2019-8141 is classified as a critical vulnerability due to its potential for remote code execution by authenticated users.
How do I fix CVE-2019-8141?
To resolve CVE-2019-8141, upgrade to Magento version 2.1.19, 2.2.10, or 2.3.3.
What versions of Magento are affected by CVE-2019-8141?
CVE-2019-8141 affects Magento versions 2.1 prior to 2.1.19, 2.2 prior to 2.2.10, and 2.3 prior to 2.3.3.
Who can exploit CVE-2019-8141?
An authenticated user with administrative privileges can exploit CVE-2019-8141 through the Phar deserialization vulnerability.
What type of vulnerability is CVE-2019-8141?
CVE-2019-8141 is a remote code execution vulnerability linked to a deserialization flaw in Magento's import functionality.