GHSA-6wm4-3rjj-c8xx

Suggest an improvement
Source
https://github.com/advisories/GHSA-6wm4-3rjj-c8xx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-6wm4-3rjj-c8xx/GHSA-6wm4-3rjj-c8xx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-6wm4-3rjj-c8xx
Published
2024-05-15T22:33:24Z
Modified
2024-05-15T22:33:25Z
Summary
Magento Security enhancements that help close RCE,XSS,CSRF and other vulnerabilities
Details

SUPEE-10975, Magento Commerce 1.14.4.0 and Open Source 1.9.4.0 contain multiple security enhancements that help close remote code execution (RCE), cross-site scripting (XSS), cross-site request forgery (CSRF) and other vulnerabilities.

References

Affected packages

Packagist / magento/community-edition

Package

Name
magento/community-edition
Purl
pkg:composer/magento/community-edition

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.5.0.0
Fixed
1.9.4.0