CVE Vulnerabilities

CVE-2019-8107

Published: Nov 05, 2019 | Modified: Aug 24, 2020
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

An arbitrary file deletion vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with export data transfer privileges can craft a request to perform arbitrary file deletion.

Affected Software

Name Vendor Start Version End Version
Magento Magento 2.2.0 (including) 2.2.10 (excluding)
Magento Magento 2.3.0 (including) 2.3.2 (excluding)
Magento Magento 2.3.2 (including) 2.3.2 (including)

References