CVE Vulnerabilities

CVE-2015-3457

Improper Authentication

Published: Apr 29, 2015 | Modified: Dec 06, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allow remote attackers to bypass authentication via the forwarded parameter.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Magento Magento 1.9.1.0 (including) 1.9.1.0 (including)
Magento Magento 1.14.1.0 (including) 1.14.1.0 (including)

Potential Mitigations

References