First published: Wed Jul 29 2020(Updated: )
Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a path traversal vulnerability. Successful exploitation could lead to arbitrary code execution.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/magento/project-community-edition | <=2.0.2 | |
composer/magento/community-edition | <2.3.5-p2 | 2.3.5-p2 |
CentOS Libgcc | <2.3.5 | |
CentOS Libgcc | <2.3.5 | |
CentOS Libgcc | =2.3.5 | |
CentOS Libgcc | =2.3.5 | |
CentOS Libgcc | =2.3.5-p1 | |
CentOS Libgcc | =2.3.5-p1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9689 is a path traversal vulnerability in Magento versions 2.3.5-p1 and earlier.
CVE-2020-9689 has a severity rating of 6.5 (high).
CVE-2020-9689 can be exploited to execute arbitrary code.
Magento versions 2.3.5-p1 and earlier are affected by CVE-2020-9689.
To fix CVE-2020-9689, you should update Magento to version 2.3.5-p2 or later.