CVE-2020-3718: Critical severity Magento Magento vulnerability
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/magneto/coreto a version that resolves this vulnerability.Fixed in 1.9.4.4 - Upgrade
Upgrade
composer/magento/community-editionto a version that resolves this vulnerability.Fixed in 2.2.11 - Upgrade
Upgrade
composer/magento/community-editionto a version that resolves this vulnerability.Fixed in 2.3.4
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3718?
CVE-2020-3718 is considered a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2020-3718?
To fix CVE-2020-3718, update your Magento version to 1.9.4.4, 2.2.11, or 2.3.4.
What versions are affected by CVE-2020-3718?
CVE-2020-3718 affects Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier.
What are the consequences of exploiting CVE-2020-3718?
Exploitation of CVE-2020-3718 could allow attackers to execute arbitrary code on the vulnerable Magento installation.
How can I determine if my Magento installation is vulnerable to CVE-2020-3718?
To determine if your Magento installation is vulnerable to CVE-2020-3718, check the version against the affected versions listed in the advisory.