GHSA-5gmh-85x8-5cx7

Suggest an improvement
Source
https://github.com/advisories/GHSA-5gmh-85x8-5cx7
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-5gmh-85x8-5cx7/GHSA-5gmh-85x8-5cx7.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5gmh-85x8-5cx7
Published
2024-05-15T22:34:08Z
Modified
2024-11-29T05:41:54.846851Z
Summary
Magento remote code execution (RCE), Cross-Site Scripting (XSS) and other vulnerabilities
Details

Magento Commerce and Open Source 2.2.5 and 2.1.14 contain multiple security enhancements that help close authenticated Admin user remote code execution (RCE), Cross-Site Scripting (XSS) and other vulnerabilities.

Database specific
{
    "nvd_published_at": null,
    "cwe_ids": [],
    "severity": "CRITICAL",
    "github_reviewed": true,
    "github_reviewed_at": "2024-05-15T22:34:08Z"
}
References

Affected packages

Packagist / magento/community-edition

Package

Name
magento/community-edition
Purl
pkg:composer/magento/community-edition

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.1
Fixed
2.1.14

Affected versions

2.*

2.1.0-rc1
2.1.0-rc2
2.1.0-rc3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.10
2.1.11
2.1.12
2.1.13

Packagist / magento/community-edition

Package

Name
magento/community-edition
Purl
pkg:composer/magento/community-edition

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.2
Fixed
2.2.5

Affected versions

2.*

2.2.0
2.2.1
2.2.2
2.2.3
2.2.4