CVE-2020-15151: Observable Timing Discrepancy in OpenMage LTS
OpenMage LTS before versions 19.4.6 and 20.0.2 allows attackers to circumvent the fromkey protection in the Admin Interface and increases the attack surface for Cross Site Request Forgery attacks. This issue is related to Adobe's CVE-2020-9690. It is patched in versions 19.4.6 and 20.0.2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-15151?
CVE-2020-15151 is a vulnerability in OpenMage LTS before versions 19.4.6 and 20.0.2 that allows attackers to circumvent the `fromkey protection` and increases the attack surface for Cross Site Request Forgery attacks.
Which versions of OpenMage LTS are affected by CVE-2020-15151?
Versions of OpenMage LTS up to and including 19.4.6, and versions between 20.0.0 and 20.0.2 are affected by CVE-2020-15151.
How severe is CVE-2020-15151?
CVE-2020-15151 is classified as high severity with a severity score of 8 out of 10.
How can I fix CVE-2020-15151?
To fix CVE-2020-15151, you should update OpenMage LTS to versions 19.4.6 or 20.0.2.
Where can I find more information about CVE-2020-15151?
You can find more information about CVE-2020-15151 at the following references: [Github Commit](https://github.com/OpenMage/magento-lts/commit/7c526bc6a6a51b57a1bab4c60f104dc36cde347a), [Github Security Advisory](https://github.com/OpenMage/magento-lts/security/advisories/GHSA-crf2-xm6x-46p6), [Adobe Security Bulletin](https://helpx.adobe.com/security/products/magento/apsb20-47.html).