CVE-2020-9588
published 2020-06-26CVE-2020-9588: Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an observable timing discrepancy…
PriorityP339high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
2.54%
83.1th percentile
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an observable timing discrepancy vulnerability. Successful exploitation could lead to signature verification bypass.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | magento | — | — |
| magento | community-edition | >= 0 < 2.3.4-p2 | 2.3.4-p2 |
| magento | core | >= 0 < 1.9.4.5 | 1.9.4.5 |
| magento | magento | <= 1.9.4.4 | — |
| magento | magento | <= 1.14.4.4 | — |
| magento | magento | 2.2.0 – 2.2.11 | — |
| magento | magento | 2.3.0 – 2.3.4 | — |
| magento | project-community-edition | 0 – 2.0.2 | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Magento Signature verification bypass
ghsa·2022-05-24
CVE-2020-9588 [HIGH] CWE-203 Magento Signature verification bypass
Magento Signature verification bypass
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an observable timing discrepancy vulnerability. Successful exploitation could lead to signature verification bypass.
OSV
Magento Signature verification bypass
osv·2022-05-24
CVE-2020-9588 [HIGH] Magento Signature verification bypass
Magento Signature verification bypass
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an observable timing discrepancy vulnerability. Successful exploitation could lead to signature verification bypass.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-06-26
Published