CVE-2019-8141Deserialization of Untrusted Data in Magento

Severity
7.2HIGHNVD
EPSS
1.6%
top 18.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 6
Latest updateMay 24

Description

A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated user with administrative privileges (system level import) can execute arbitrary code through a Phar deserialization vulnerability in the import functionality.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages3 packages

CVEListV5adobe_systems_incorporated/magento_2Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1+1
NVDmagento/magento2.1.02.1.19+3
Packagistmagento/community-edition2.1.02.1.19+2

Patches

🔴Vulnerability Details

3
GHSA
Magento 2 Community Edition RCE Vulnerability2022-05-24
OSV
Magento 2 Community Edition RCE Vulnerability2022-05-24
CVEList
CVE-2019-8141: A remote code execution vulnerability exists in Magento 22019-11-05
CVE-2019-8141 — Deserialization of Untrusted Data | cvebase