CVE-2019-7950Authorization Bypass Through User-Controlled Key in Magento

Severity
7.5HIGHNVD
EPSS
0.4%
top 39.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 2
Latest updateMay 24

Description

An access control bypass vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An unauthenticated user can bypass access controls via REST API calls to assign themselves to an arbitrary company, thereby gaining read access to potentially confidental information.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDmagento/magento2.1.02.1.18+2
Packagistmagento/community-edition2.1.02.1.18+2
CVEListV5adobe_systems_incorporated/magento_2Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2

🔴Vulnerability Details

3
OSV
Magento 2 Community Edition Access Control Bypass2022-05-24
GHSA
Magento 2 Community Edition Access Control Bypass2022-05-24
CVEList
CVE-2019-7950: An access control bypass vulnerability exists in Magento 22019-08-02
CVE-2019-7950 — Magento vulnerability | cvebase