CVE-2019-8144: Critical severity centos libgcc vulnerability
Published Oct 8, 2019
·Updated
A remote code execution vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can insert a malicious payload through PageBuilder template methods.
Other sources
PRODSECBUG-2403: Remote code execution through crafted PageBuilder templates
Affected Software
6 affected componentsFixes available
composer/magento/product-community-edition>=2.2, <2.2.10, >=2.3, <2.3.2-p2
composer/magento/community-edition>=2.3<2.3.2-p1
2.3.2-p1
Magento Magento>=2.3.0<2.3.2
Magento Magento>=2.3.0<2.3.2
Magento Magento=2.3.2
Magento Magento=2.3.2
Remediation
Event History
Oct 8, 2019
Advisory Published
12:00 AM
Nov 5, 2019
CVE Published
via MITRE·11:30 PM
Data Sourced
via MITRE·11:30 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-8144?
CVE-2019-8144 is categorized as a critical remote code execution vulnerability.
2
How do I fix CVE-2019-8144?
To fix CVE-2019-8144, upgrade Magento to version 2.3.2-p1 or later.
3
Who is affected by CVE-2019-8144?
CVE-2019-8144 affects Magento versions prior to 2.3.3 and those specifically from 2.2.0 to 2.2.10.
4
What can an attacker do with CVE-2019-8144?
An attacker can exploit CVE-2019-8144 to execute arbitrary code on the affected Magento systems.
5
Is authentication needed to exploit CVE-2019-8144?
CVE-2019-8144 can be exploited by an unauthenticated user, making it particularly dangerous.