Insufficient enforcement of user access controls in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could enable a low-privileged user to make unauthorized environment configuration changes.
{ "versions": [ { "introduced": "2.1.0" }, { "fixed": "2.1.18" }, { "introduced": "2.2.0" }, { "fixed": "2.2.9" }, { "introduced": "2.3.0" }, { "fixed": "2.3.2" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-7904.json"