CVE-2020-9578: Command Injection
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-9578?
CVE-2020-9578 is classified as a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2020-9578?
To mitigate CVE-2020-9578, upgrade to Magento version 1.9.4.5, 2.3.4-p2, or any later version.
Which versions of Magento are affected by CVE-2020-9578?
CVE-2020-9578 affects Magento versions 2.3.4 and earlier, 2.2.11 and earlier, 1.14.4.4 and earlier, and 1.9.4.4 and earlier.
What types of attacks are possible with CVE-2020-9578?
Successful exploitation of CVE-2020-9578 could allow an attacker to execute arbitrary commands on the affected Magento installation.
Is there a public exploit available for CVE-2020-9578?
As of now, there are no confirmed public exploits for CVE-2020-9578, but due to its severity, it is highly recommended to apply the necessary patches promptly.