CVE-2019-8232
Severity CVSS v4.0:
Pending analysis
Type:
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Publication date:
06/11/2019
Last modified:
24/08/2020
Description
In Magento prior to 1.9.4.3, Magento prior to 1.14.4.3, Magento 2.2 prior to 2.2.10, and Magento 2.3 prior to 2.3.3 or 2.3.2-p1, an authenticated user with administrative privileges for the import feature can execute arbitrary code through a race condition that allows webserver configuration file modification.
Impact
Base Score 3.x
6.60
Severity 3.x
MEDIUM
Base Score 2.0
6.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:* | 1.5.0.0 (including) | 1.9.4.3 (excluding) |
| cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:* | 1.9.0.0 (including) | 1.14.4.3 (excluding) |
| cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:* | 2.2.0 (including) | 2.2.10 (excluding) |
| cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:* | 2.2.0 (including) | 2.2.10 (excluding) |
| cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:* | 2.3.0 (including) | 2.3.2 (excluding) |
| cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:* | 2.3.0 (including) | 2.3.2 (excluding) |
| cpe:2.3:a:magento:magento:2.3.2:-:*:*:commerce:*:*:* | ||
| cpe:2.3:a:magento:magento:2.3.2:-:*:*:open_source:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



