CVE-2019-8158: Critical severity centos libgcc vulnerability
An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An attacker can craft a GET request to page cache block rendering module that gets passed to XML data processing engine without validation. The crafted key/value GET request data allows an attacker to limited access to underlying XML data.
Other sources
PRODSECBUG-2272: XPath Injection via front end rendering functionality
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8158?
CVE-2019-8158 is rated as a medium severity vulnerability due to the potential for XPath entity injection.
How do I fix CVE-2019-8158?
To fix CVE-2019-8158, upgrade Magento to version 2.2.10 or 2.3.3 and higher.
Which versions of Magento are affected by CVE-2019-8158?
CVE-2019-8158 affects Magento versions 2.2.0 to 2.2.9 and 2.3.0 to 2.3.2.
Can I check if my Magento site is vulnerable to CVE-2019-8158?
You can check your Magento version against the affected ranges to determine if your site is vulnerable to CVE-2019-8158.
What types of attacks can be executed due to CVE-2019-8158?
CVE-2019-8158 allows attackers to exploit unvalidated input leading to potential XPath entity injection attacks.