CVE-2020-9689: Path Traversal
Published Jul 29, 2020
·Updated
Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a path traversal vulnerability. Successful exploitation could lead to arbitrary code execution.
Affected Software
8 affected componentsFixes available
composer/magento/project-community-edition<=2.0.2
composer/magento/community-edition<2.3.5-p2
2.3.5-p2
Magento Magento<2.3.5
Magento Magento<2.3.5
Magento Magento=2.3.5
Magento Magento=2.3.5
Magento Magento=2.3.5-p1
Magento Magento=2.3.5-p1
Remediation
Event History
Jul 29, 2020
CVE Published
via MITRE·12:20 PM
Data Sourced
via MITRE·12:20 PM
DescriptionWeakness
Data Sourced
via NVD·01:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 24, 2022
Advisory Published
via GitHub·05:24 PM
Data Sourced
via GitHub·05:24 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-9689?
CVE-2020-9689 is a path traversal vulnerability in Magento versions 2.3.5-p1 and earlier.
2
What is the severity of CVE-2020-9689?
CVE-2020-9689 has a severity rating of 6.5 (high).
3
How can CVE-2020-9689 be exploited?
CVE-2020-9689 can be exploited to execute arbitrary code.
4
Which versions of Magento are affected by CVE-2020-9689?
Magento versions 2.3.5-p1 and earlier are affected by CVE-2020-9689.
5
How can I fix CVE-2020-9689?
To fix CVE-2020-9689, you should update Magento to version 2.3.5-p2 or later.