PT-2020-6327 · Adobe · Magento

CVE-2020-9585

·

Published

2020-04-28

·

Updated

2024-03-06

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Magento versions 2.3.4 and earlier Magento versions 2.2.11 and earlier Magento versions 1.14.4.4 and earlier Magento versions 1.9.4.4 and earlier
Description The issue is related to incorrect code generation management in the Magento Commerce platform. It may allow a remote attacker to execute arbitrary code.
Recommendations For versions 2.3.4 and earlier, update to a version that includes the security mitigation. For versions 2.2.11 and earlier, update to a version that includes the security mitigation. For versions 1.14.4.4 and earlier, update to a version that includes the security mitigation. For versions 1.9.4.4 and earlier, update to a version that includes the security mitigation.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04188
BIT-MAGENTO-2020-9585
CVE-2020-9585
GHSA-55GV-HFG3-HWJQ

Affected Products

Magento