CVE-2020-9580: Critical severity centos libgcc vulnerability
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-9580?
CVE-2020-9580 has a high severity rating due to its potential to allow arbitrary code execution.
How do I fix CVE-2020-9580?
To fix CVE-2020-9580, upgrade to Magento version 1.9.4.5 or 2.3.4-p2.
Which Magento versions are affected by CVE-2020-9580?
Magento versions 2.3.4 and earlier, 2.2.11 and earlier, as well as 1.14.4.4 and earlier, and 1.9.4.4 and earlier are affected by CVE-2020-9580.
What consequences can arise from exploiting CVE-2020-9580?
Exploiting CVE-2020-9580 can lead to arbitrary code execution on affected Magento installations.
Is there a workaround for CVE-2020-9580?
Currently, the only effective solution for CVE-2020-9580 is to apply the recommended updates to your Magento installation.