HIGH7.5
GHSA-8wm7-h2qh-ff4c
Magento authorization bypass vulnerability
Quick fix
GHSA-8wm7-h2qh-ff4c — magento/community-edition: upgrade to the fixed version with the command below.
composer require magento/community-edition:^2.3.4-p2Details
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an authorization bypass vulnerability. Successful exploitation could lead to potentially unauthorized product discounts.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/magento/community-edition
Introduced in:
0No fixed version published yet for magento/community-edition (composer). Pin to a known-safe version or switch to an alternative.
Packagist/magento/community-edition
Introduced in:
2.3.0Fixed in: 2.3.4-p2Fix
composer require magento/community-edition:^2.3.4-p2Packagist/magento/project-community-edition
Introduced in:
0No fixed version published yet for magento/project-community-edition (composer). Pin to a known-safe version or switch to an alternative.