Insufficient input validation in the config builder of the Elastic search module could lead to remote code execution in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This vulnerability could be abused by an authenticated user with the ability to configure the catalog search.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published: 2019-08-02T21:20:53

Updated: 2024-08-04T21:02:19.254Z

Reserved: 2019-02-12T00:00:00

Link: CVE-2019-7885

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-08-02T22:15:16.567

Modified: 2019-08-07T18:47:24.757

Link: CVE-2019-7885

cve-icon Redhat

No data.