CVE-2020-9690: Medium severity centos libgcc vulnerability
Published Jul 29, 2020
·Updated
Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have an observable timing discrepancy vulnerability. Successful exploitation could lead to signature verification bypass.
Affected Software
7 affected componentsFixes available
composer/magento/community-edition<2.3.5-p2
2.3.5-p2
Magento Magento<2.3.5
Magento Magento<2.3.5
Magento Magento=2.3.5
Magento Magento=2.3.5
Magento Magento=2.3.5-p1
Magento Magento=2.3.5-p1
Remediation
Event History
Jul 29, 2020
CVE Published
via MITRE·12:20 PM
Data Sourced
via MITRE·12:20 PM
DescriptionWeakness
May 24, 2022
Advisory Published
via GitHub·05:24 PM
Frequently Asked Questions
1
What is the vulnerability ID for this Magento vulnerability?
The vulnerability ID for this Magento vulnerability is CVE-2020-9690.
2
What is the severity of CVE-2020-9690?
The severity of CVE-2020-9690 is medium.
3
Which versions of Magento are affected by CVE-2020-9690?
Magento versions 2.3.5-p1 and earlier are affected by CVE-2020-9690.
4
What is the impact of CVE-2020-9690?
Successful exploitation of CVE-2020-9690 could lead to signature verification bypass.
5
How can I fix CVE-2020-9690?
To fix CVE-2020-9690, update Magento to version 2.3.5-p1 or later.