GHSA-8j7c-682x-r9f2

Source
https://github.com/advisories/GHSA-8j7c-682x-r9f2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-8j7c-682x-r9f2/GHSA-8j7c-682x-r9f2.json
Published
2024-05-15T22:34:11Z
Modified
2024-05-15T22:49:52.862701Z
Summary
Magento RCE,XSS and other vulnerabilities
Details

Magento Commerce and Open Source 2.3.0, 2.2.7 and 2.1.16 contain multiple security enhancements that help close Remote Code Execution (RCE), Cross-Site Scripting (XSS) and other vulnerabilities.

References

Affected packages

Packagist / magento/community-edition

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.1
Fixed
2.1.16

Affected versions

2.*

2.1.0-rc1
2.1.0-rc2
2.1.0-rc3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15

Packagist / magento/community-edition

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.2
Fixed
2.2.7

Affected versions

2.*

2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6