CVE Vulnerabilities

CVE-2019-7904

Published: Aug 02, 2019 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Insufficient enforcement of user access controls in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could enable a low-privileged user to make unauthorized environment configuration changes.

Affected Software

NameVendorStart VersionEnd Version
MagentoMagento2.1.0 (including)2.1.18 (excluding)
MagentoMagento2.2.0 (including)2.2.9 (excluding)
MagentoMagento2.3.0 (including)2.3.2 (excluding)

References