CVE-2020-15244: RCE in Magento
Published Oct 21, 2020
·Updated
In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credentials that can be used to trigger RCE via PHP Object Injection through product attributes and a product. The issue is patched in versions 19.4.8 and 20.0.4.
Affected Software
2 affected components
OpenMage Magento<=19.4.8
OpenMage Magento>=20.0.0<20.0.4
Remediation
Event History
Oct 21, 2020
CVE Published
via MITRE·08:05 PM
Data Sourced
via MITRE·08:05 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Magento vulnerability?
The vulnerability ID for this Magento vulnerability is CVE-2020-15244.
2
What is the severity level of CVE-2020-15244?
The severity level of CVE-2020-15244 is high.
3
How can an admin user trigger remote code execution (RCE) through product attributes and a product?
An admin user can trigger RCE through product attributes and a product by generating soap credentials that can be used for PHP Object Injection.
4
Which versions of Magento are affected by CVE-2020-15244?
Versions 19.4.8 and 20.0.4 of Magento are affected by CVE-2020-15244.
5
Is there a patch available for CVE-2020-15244?
Yes, the issue is patched in versions 19.4.8 and 20.0.4 of Magento.