CVE Vulnerabilities

CVE-2019-8136

Published: Nov 06, 2019 | Modified: Nov 08, 2019
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

An insecure component vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Magento 2 codebase leveraged outdated versions of HTTP specification abstraction implemented in symphony component.

Affected Software

Name Vendor Start Version End Version
Magento Magento 2.2.0 (including) 2.2.10 (excluding)
Magento Magento 2.3.0 (including) 2.3.2 (excluding)
Magento Magento 2.3.2 (including) 2.3.2 (including)

References