CVE-2020-9582: OS Command Injection
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-9582?
CVE-2020-9582 has a critical severity rating due to its command injection vulnerability that allows arbitrary code execution.
How do I fix CVE-2020-9582?
To mitigate CVE-2020-9582, upgrade to Magento version 1.9.4.5 or later, 2.2.12 or later, or 2.3.4-p2 or later.
What versions of Magento are affected by CVE-2020-9582?
CVE-2020-9582 affects Magento versions 2.3.4 and earlier, 2.2.11 and earlier, and earlier versions of Magento 1.14.4.4 and 1.9.4.4.
What type of vulnerability is CVE-2020-9582?
CVE-2020-9582 is a command injection vulnerability which could lead to arbitrary code execution when exploited.
Is CVE-2020-9582 still a risk if I have updated Magento?
CVE-2020-9582 is no longer a risk if your Magento installation has been updated to the recommended versions 1.9.4.5, 2.2.12, or 2.3.4-p2.