CVE-2020-9591: Infoleak
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth security mitigation vulnerability. Successful exploitation could lead to unauthorized access to admin panel.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Magento vulnerability?
The vulnerability ID for this Magento vulnerability is CVE-2020-9591.
What versions of Magento are affected by this vulnerability?
Magento versions 2.3.4 and earlier, 2.2.11 and earlier, 1.14.4.4 and earlier, and 1.9.4.4 and earlier are affected by this vulnerability.
What is the severity of CVE-2020-9591?
The severity of CVE-2020-9591 is high.
What is the impact of this vulnerability?
Successful exploitation of this vulnerability could lead to unauthorized access to the admin panel.
Is there a patch available for this vulnerability?
Yes, a patch is available to fix this vulnerability. Please refer to the official Magento security advisory for more information and instructions on applying the patch.