CVE-2019-8123Insufficient Logging in Magento

Severity
5.3MEDIUMNVD
EPSS
0.1%
top 74.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 5
Latest updateMay 24

Description

An insufficient logging and monitoring vulnerability exists in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. The logging feature required for effective monitoring did not contain sufficent data to effectively track configuration changes.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

NVDmagento/magento2.2.02.2.10+3
Packagistmagento/community-edition2.1.02.1.19+2
CVEListV5adobe_systems_incorporated/magento_1_2Magento Open Source prior to 1.9.4.3, and Magento Commerce prior to 1.14.4.3, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p2

Patches

🔴Vulnerability Details

3
OSV
Magento 2 Community Edition Insufficient Logging2022-05-24
GHSA
Magento 2 Community Edition Insufficient Logging2022-05-24
CVEList
CVE-2019-8123: An insufficient logging and monitoring vulnerability exists in Magento 1 prior to 12019-11-05
CVE-2019-8123 — Insufficient Logging in Magento | cvebase