CVE-2019-8232: Race Condition
In Magento prior to 1.9.4.3, Magento prior to 1.14.4.3, Magento 2.2 prior to 2.2.10, and Magento 2.3 prior to 2.3.3 or 2.3.2-p1, an authenticated user with administrative privileges for the import feature can execute arbitrary code through a race condition that allows webserver configuration file modification.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8232?
CVE-2019-8232 is considered a critical vulnerability due to the potential for an authenticated user to execute arbitrary code.
How do I fix CVE-2019-8232?
To fix CVE-2019-8232, upgrade to Magento version 2.3.2-p1, 2.2.10, 1.9.4.3, or 1.14.4.3.
Who is affected by CVE-2019-8232?
CVE-2019-8232 affects Magento versions prior to 2.3.3, 2.2.10, 1.9.4.3, and 1.14.4.3.
What can an attacker do with CVE-2019-8232?
An attacker with administrative privileges can exploit CVE-2019-8232 to execute arbitrary code on the web server.
Is CVE-2019-8232 an authenticated or unauthenticated vulnerability?
CVE-2019-8232 is an authenticated vulnerability, meaning it requires the attacker to have valid administrative credentials.