CVE-2020-9588: High severity centos libgcc vulnerability
Published Jun 26, 2020
·Updated
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an observable timing discrepancy vulnerability. Successful exploitation could lead to signature verification bypass.
Affected Software
9 affected componentsFixes available
composer/magento/project-community-edition<=2.0.2
composer/magento/core<1.9.4.5
1.9.4.5
composer/magento/community-edition<2.3.4-p2
2.3.4-p2
Magento Magento<=1.9.4.4
Magento Magento<=1.14.4.4
Magento Magento>=2.2.0<=2.2.11
Magento Magento>=2.2.0<=2.2.11
Magento Magento>=2.3.0<=2.3.4
Magento Magento>=2.3.0<=2.3.4
Event History
Jun 26, 2020
CVE Published
via MITRE·08:20 PM
Data Sourced
via MITRE·08:20 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
May 24, 2022
Advisory Published
via GitHub·05:21 PM
Data Sourced
via GitHub·05:21 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this Magento vulnerability?
The vulnerability ID for this Magento vulnerability is CVE-2020-9588.
2
What is the severity level of CVE-2020-9588?
CVE-2020-9588 has a severity level of high (7.2).
3
Which versions of Magento are affected by CVE-2020-9588?
Versions 2.3.4 and earlier, 2.2.11 and earlier, 1.14.4.4 and earlier, and 1.9.4.4 and earlier are affected by CVE-2020-9588.
4
What is the impact of successful exploitation of CVE-2020-9588?
Successful exploitation of CVE-2020-9588 could lead to signature verification bypass.
5
Is there a fix available for CVE-2020-9588?
Yes, a fix is available for CVE-2020-9588. Please refer to the official reference link for more information.