CVE-2020-3717: Path Traversal
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a path traversal vulnerability. Successful exploitation could lead to sensitive information disclosure.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/magento/community-editionto a version that resolves this vulnerability.Fixed in 2.3.4 - Upgrade
Upgrade
composer/magento/community-editionto a version that resolves this vulnerability.Fixed in 2.2.11
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3717?
CVE-2020-3717 has a severity rating that indicates a moderate risk of information disclosure due to path traversal.
How do I fix CVE-2020-3717?
To fix CVE-2020-3717, upgrade to Magento version 2.3.4 or later, 2.2.11, 1.14.4.4 or later, or 1.9.4.4 or later.
Which versions of Magento are affected by CVE-2020-3717?
CVE-2020-3717 affects Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier.
What type of vulnerability is CVE-2020-3717?
CVE-2020-3717 is classified as a path traversal vulnerability.
What could happen if CVE-2020-3717 is exploited?
Exploitation of CVE-2020-3717 could lead to sensitive information disclosure within the affected Magento installations.