CVE-2019-8149: Critical severity centos libgcc vulnerability
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can append arbitrary session id that will not be invalidated by subsequent authentication.
Other sources
PRODSECBUG-2390: Broken authentication and session managememt
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8149?
CVE-2019-8149 is classified as a high severity vulnerability due to its potential for unauthenticated access and session hijacking.
How do I fix CVE-2019-8149?
To fix CVE-2019-8149, upgrade Magento to version 2.2.10 or 2.3.2-p1 or later.
What versions of Magento are affected by CVE-2019-8149?
CVE-2019-8149 affects Magento versions 2.2.0 through 2.2.9 and 2.3.0 through 2.3.2.
Can unauthenticated users exploit CVE-2019-8149?
Yes, unauthenticated users can exploit CVE-2019-8149 by appending arbitrary session IDs that are not invalidated.
What is the impact of exploiting CVE-2019-8149?
Exploitation of CVE-2019-8149 can lead to unauthorized access to user sessions, compromising sensitive data and account integrity.