Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Magento | Magento | * | 1.9.4.3 (including) |
Magento | Magento | * | 1.14.4.3 (including) |
Magento | Magento | 2.2.0 (including) | 2.2.10 (including) |
Magento | Magento | 2.3.0 (including) | 2.3.3 (including) |