An access control bypass vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An unauthenticated user can bypass access controls via REST API calls to assign themselves to an arbitrary company, thereby gaining read access to potentially confidental information.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-1974 An access control bypass vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An unauthenticated user can bypass access controls via REST API calls to assign themselves to an arbitrary company, thereby gaining read access to potentially confidental information.
Github GHSA Github GHSA GHSA-2fhr-f6q6-c4p2 Magento 2 Community Edition Access Control Bypass
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2024-08-04T21:02:19.442Z

Reserved: 2019-02-12T00:00:00

Link: CVE-2019-7950

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-08-02T22:15:19.427

Modified: 2024-11-21T04:48:59.833

Link: CVE-2019-7950

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.