HIGH7.2
GHSA-j2r4-2cr6-h3r3
Magento Signature verification bypass
Quick fix
GHSA-j2r4-2cr6-h3r3 — magento/community-edition: upgrade to the fixed version with the command below.
composer require magento/community-edition:^2.3.4-p2Details
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an observable timing discrepancy vulnerability. Successful exploitation could lead to signature verification bypass.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/magento/community-edition
Introduced in:
0Fixed in: 2.3.4-p2Fix
composer require magento/community-edition:^2.3.4-p2Packagist/magento/project-community-edition
Introduced in:
0No fixed version published yet for magento/project-community-edition (composer). Pin to a known-safe version or switch to an alternative.