CVE-2019-8108
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
05/11/2019
Last modified:
07/11/2019
Description
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can manipulate session validation setting for a storefront that leads to insecure authentication and session management.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:* | 2.2.0 (including) | 2.2.10 (excluding) |
| cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:* | 2.2.0 (including) | 2.2.10 (excluding) |
| cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:* | 2.3.0 (including) | 2.3.2 (excluding) |
| cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:* | 2.3.0 (including) | 2.3.2 (excluding) |
| cpe:2.3:a:magento:magento:2.3.2:-:*:*:commerce:*:*:* | ||
| cpe:2.3:a:magento:magento:2.3.2:-:*:*:open_source:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



