CVE-2019-7915Magento vulnerability

4 documents4 sources
Severity
7.5HIGHNVD
EPSS
0.3%
top 47.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 2
Latest updateMay 24

Description

A denial-of-service vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Under certain conditions, an unauthenticated attacker could force the Magento store's full page cache to serve a 404 page to customers.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDmagento/magento2.1.02.1.18+2
Packagistmagento/community-edition2.1.02.1.18+2
CVEListV5adobe_systems_incorporated/magento_2Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2

🔴Vulnerability Details

3
GHSA
Magento 2 Community Edition DoS vulnerability2022-05-24
OSV
Magento 2 Community Edition DoS vulnerability2022-05-24
CVEList
CVE-2019-7915: A denial-of-service vulnerability exists in Magento 22019-08-02
CVE-2019-7915 — Magento vulnerability | cvebase