An access control bypass vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An unauthenticated user can bypass access controls via REST API calls to assign themselves to an arbitrary company, thereby gaining read access to potentially confidental information.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1974 | An access control bypass vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An unauthenticated user can bypass access controls via REST API calls to assign themselves to an arbitrary company, thereby gaining read access to potentially confidental information. |
Github GHSA |
GHSA-2fhr-f6q6-c4p2 | Magento 2 Community Edition Access Control Bypass |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: adobe
Published:
Updated: 2024-08-04T21:02:19.442Z
Reserved: 2019-02-12T00:00:00
Link: CVE-2019-7950
No data.
Status : Modified
Published: 2019-08-02T22:15:19.427
Modified: 2024-11-21T04:48:59.833
Link: CVE-2019-7950
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA