CVE Vulnerabilities

CVE-2019-7915

Published: Aug 02, 2019 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A denial-of-service vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Under certain conditions, an unauthenticated attacker could force the Magento stores full page cache to serve a 404 page to customers.

Affected Software

NameVendorStart VersionEnd Version
MagentoMagento2.1.0 (including)2.1.18 (excluding)
MagentoMagento2.2.0 (including)2.2.9 (excluding)
MagentoMagento2.3.0 (including)2.3.2 (excluding)

References