HIGH8.8
GHSA-6qh6-v99h-vh4c
Magento 2 Community Edition RCE Vulnerability
Quick fix
GHSA-6qh6-v99h-vh4c — magento/community-edition: upgrade to the fixed version with the command below.
composer require magento/community-edition:^2.1.18Details
A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with privileges to manipulate layouts can insert a malicious payload into the layout.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/magento/community-edition
Introduced in:
2.1Fixed in: 2.1.18Fix
composer require magento/community-edition:^2.1.18Packagist/magento/community-edition
Introduced in:
2.2Fixed in: 2.2.9Fix
composer require magento/community-edition:^2.2.9Packagist/magento/community-edition
Introduced in:
2.3Fixed in: 2.3.2Fix
composer require magento/community-edition:^2.3.2Packagist/magento/product-community-edition
Introduced in:
2.1Fixed in: 2.1.18Fix
composer require magento/product-community-edition:^2.1.18Packagist/magento/product-community-edition
Introduced in:
2.2Fixed in: 2.2.9Fix
composer require magento/product-community-edition:^2.2.9Packagist/magento/product-community-edition
Introduced in:
2.3Fixed in: 2.3.2Fix
composer require magento/product-community-edition:^2.3.2References
- https://nvd.nist.gov/vuln/detail/CVE-2019-7876[ADVISORY]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/magento/product-community-edition/CVE-2019-7876.yaml[WEB]
- https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-13[WEB]
- https://web.archive.org/web/20211206084839/https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-13[WEB]