First published: Wed Jul 29 2020(Updated: )
Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/magento/community-edition | <2.3.5-p2 | 2.3.5-p2 |
Magento Magento | <2.3.5 | |
Magento Magento | <2.3.5 | |
Magento Magento | =2.3.5 | |
Magento Magento | =2.3.5 | |
Magento Magento | =2.3.5-p1 | |
Magento Magento | =2.3.5-p1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9692 is a security mitigation bypass vulnerability in Magento versions 2.3.5-p1 and earlier.
CVE-2020-9692 has a severity rating of high.
Successful exploitation of CVE-2020-9692 could lead to arbitrary code execution.
Magento versions 2.3.5-p1 and earlier are affected by CVE-2020-9692.
Yes, a fix for CVE-2020-9692 is available. It is recommended to update to Magento versions 2.3.5-p2 or later.