Description
A server-side request forgery (SSRF) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with admin privileges to modify store configurations can manipulate the connector api endpoint to enable remote code execution.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2937 | A server-side request forgery (SSRF) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with admin privileges to modify store configurations can manipulate the connector api endpoint to enable remote code execution. |
Github GHSA |
GHSA-775w-gx3f-4j4f | Magento 2 Community Edition SSRF vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: adobe
Published:
Updated: 2024-08-04T21:10:33.446Z
Reserved: 2019-02-12T00:00:00.000Z
Link: CVE-2019-8156
No data.
Status : Modified
Published: 2019-11-06T01:15:25.310
Modified: 2024-11-21T04:49:23.387
Link: CVE-2019-8156
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA