In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credentials that can be used to trigger RCE via PHP Object Injection through product attributes and a product. The issue is patched in versions 19.4.8 and 20.0.4.
References
Link | Resource |
---|---|
https://github.com/OpenMage/magento-lts | Vendor Advisory |
https://github.com/OpenMage/magento-lts/commit/26433d15b57978fcb7701b5f99efe8332ca8630b | Patch Vendor Advisory |
https://github.com/OpenMage/magento-lts/security/advisories/GHSA-jrgf-vfw2-hj26 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: GitHub_M
Published: 2020-10-21T20:05:20
Updated: 2020-10-21T20:05:20
Reserved: 2020-06-25T00:00:00
Link: CVE-2020-15244
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-10-21T20:15:13.443
Modified: 2021-11-18T16:21:59.120
Link: CVE-2020-15244
JSON object: View
Redhat Information
No data.