An information leakage vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with administrator privileges may be able to view metadata of a trusted device used by another administrator via a crafted http request.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-4064 An information leakage vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with administrator privileges may be able to view metadata of a trusted device used by another administrator via a crafted http request.
Github GHSA Github GHSA GHSA-h522-94xp-2xr6 Magento 2 Community Edition Information Disclosure
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2024-08-04T21:02:19.436Z

Reserved: 2019-02-12T00:00:00

Link: CVE-2019-7929

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-08-02T22:15:18.423

Modified: 2024-11-21T04:48:57.990

Link: CVE-2019-7929

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.