First published: Wed Jul 29 2020(Updated: )
Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have an observable timing discrepancy vulnerability. Successful exploitation could lead to signature verification bypass.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/magento/community-edition | <2.3.5-p2 | 2.3.5-p2 |
Magento Magento | <2.3.5 | |
Magento Magento | <2.3.5 | |
Magento Magento | =2.3.5 | |
Magento Magento | =2.3.5 | |
Magento Magento | =2.3.5-p1 | |
Magento Magento | =2.3.5-p1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Magento vulnerability is CVE-2020-9690.
The severity of CVE-2020-9690 is medium.
Magento versions 2.3.5-p1 and earlier are affected by CVE-2020-9690.
Successful exploitation of CVE-2020-9690 could lead to signature verification bypass.
To fix CVE-2020-9690, update Magento to version 2.3.5-p1 or later.