Adobe (Magento) Update
3203Warning Date
Severity Level
Warning Number
Target Sector
30 January, 2020
● Critical
2020-859
All
Description:
Magento has released security update to address multiple vulnerabilities in the following versions:
- Magento Commerce
- 2.3.3 and earlier versions
- 2.2.10 and earlier versions
- Magento Open Source
- 2.3.3 and earlier versions
- 2.2.10 and earlier versions
- Magento Enterprise Edition
- 1.14.4.3 and earlier versions
- Magento Community Edition
- 1.9.4.3 and earlier versions
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Cross-site scripting (XSS) attack which may lead to sensitive information disclosure.
- Bypass security restrictions.
- Arbitrary code execution.
Best practice and Recommendations:
The CERT team encourages users to review Adobe security advisory and apply the necessary updates: