CVE-2020-9692: High severity Magento Magento vulnerability
Published Jul 29, 2020
·Updated
Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
Affected Software
7 affected componentsFixes available
composer/magento/community-edition<2.3.5-p2
2.3.5-p2
Magento Magento<2.3.5
Magento Magento<2.3.5
Magento Magento=2.3.5
Magento Magento=2.3.5
Magento Magento=2.3.5-p1
Magento Magento=2.3.5-p1
Remediation
Event History
Jul 29, 2020
CVE Published
via MITRE·12:20 PM
Data Sourced
via MITRE·12:20 PM
DescriptionWeakness
May 24, 2022
Advisory Published
via GitHub·05:24 PM
Frequently Asked Questions
1
What is CVE-2020-9692?
CVE-2020-9692 is a security mitigation bypass vulnerability in Magento versions 2.3.5-p1 and earlier.
2
What is the severity of CVE-2020-9692?
CVE-2020-9692 has a severity rating of high.
3
How can CVE-2020-9692 be exploited?
Successful exploitation of CVE-2020-9692 could lead to arbitrary code execution.
4
Which versions of Magento are affected by CVE-2020-9692?
Magento versions 2.3.5-p1 and earlier are affected by CVE-2020-9692.
5
Is there a fix available for CVE-2020-9692?
Yes, a fix for CVE-2020-9692 is available. It is recommended to update to Magento versions 2.3.5-p2 or later.