First published: Fri Jun 26 2020(Updated: )
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an authorization bypass vulnerability. Successful exploitation could lead to potentially unauthorized product discounts.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/magento/project-community-edition | <=2.0.2 | |
composer/magento/core | <1.9.4.5 | 1.9.4.5 |
composer/magento/community-edition | >=2.3.0<2.3.4-p2 | 2.3.4-p2 |
composer/magento/community-edition | <=2.2.11 | |
CentOS Libgcc | <=1.9.4.4 | |
CentOS Libgcc | <=1.14.4.4 | |
CentOS Libgcc | >=2.2.0<=2.2.11 | |
CentOS Libgcc | >=2.2.0<=2.2.11 | |
CentOS Libgcc | >=2.3.0<=2.3.4 | |
CentOS Libgcc | >=2.3.0<=2.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9587 is an authorization bypass vulnerability in Magento versions 2.3.4 and earlier, 2.2.11 and earlier, 1.14.4.4 and earlier, and 1.9.4.4 and earlier.
CVE-2020-9587 has a severity rating of 7.5 (high).
Successful exploitation of CVE-2020-9587 could lead to potentially unauthorized product discounts in Magento.
Magento versions 2.3.4 and earlier, 2.2.11 and earlier, 1.14.4.4 and earlier, and 1.9.4.4 and earlier are affected by CVE-2020-9587.
Updating to Magento versions 2.3.5, 2.2.12, 1.14.4.5, or 1.9.4.5 will fix the authorization bypass vulnerability.