CVE-2020-9587: High severity centos libgcc vulnerability
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an authorization bypass vulnerability. Successful exploitation could lead to potentially unauthorized product discounts.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-9587?
CVE-2020-9587 is an authorization bypass vulnerability in Magento versions 2.3.4 and earlier, 2.2.11 and earlier, 1.14.4.4 and earlier, and 1.9.4.4 and earlier.
How severe is CVE-2020-9587?
CVE-2020-9587 has a severity rating of 7.5 (high).
What is the impact of CVE-2020-9587?
Successful exploitation of CVE-2020-9587 could lead to potentially unauthorized product discounts in Magento.
Which versions of Magento are affected by CVE-2020-9587?
Magento versions 2.3.4 and earlier, 2.2.11 and earlier, 1.14.4.4 and earlier, and 1.9.4.4 and earlier are affected by CVE-2020-9587.
How can I mitigate the vulnerability described in CVE-2020-9587?
Updating to Magento versions 2.3.5, 2.2.12, 1.14.4.5, or 1.9.4.5 will fix the authorization bypass vulnerability.