CVE-2020-9585: Critical severity centos libgcc vulnerability
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth security mitigation vulnerability. Successful exploitation could lead to arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-9585?
CVE-2020-9585 is a vulnerability in Magento versions 2.3.4 and earlier, 2.2.11 and earlier, 1.14.4.4 and earlier, and 1.9.4.4 and earlier that could lead to arbitrary code execution.
How severe is CVE-2020-9585?
CVE-2020-9585 is considered critical with a severity score of 9.8.
How do I fix CVE-2020-9585?
To fix CVE-2020-9585, you should update your Magento installation to versions 2.3.5, 2.2.12, 1.14.4.5, and 1.9.4.5 or later.
Which versions of Magento are affected by CVE-2020-9585?
Magento versions 2.3.4 and earlier, 2.2.11 and earlier, 1.14.4.4 and earlier, and 1.9.4.4 and earlier are affected by CVE-2020-9585.
Where can I find more information about CVE-2020-9585?
You can find more information about CVE-2020-9585 at https://helpx.adobe.com/security/products/magento/apsb20-22.html.