First published: Wed Oct 21 2020(Updated: )
In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credentials that can be used to trigger RCE via PHP Object Injection through product attributes and a product. The issue is patched in versions 19.4.8 and 20.0.4.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenMage | <=19.4.8 | |
OpenMage | >=20.0.0<20.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Magento vulnerability is CVE-2020-15244.
The severity level of CVE-2020-15244 is high.
An admin user can trigger RCE through product attributes and a product by generating soap credentials that can be used for PHP Object Injection.
Versions 19.4.8 and 20.0.4 of Magento are affected by CVE-2020-15244.
Yes, the issue is patched in versions 19.4.8 and 20.0.4 of Magento.