GHSA-crf2-xm6x-46p6

Suggest an improvement
Source
https://github.com/advisories/GHSA-crf2-xm6x-46p6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/08/GHSA-crf2-xm6x-46p6/GHSA-crf2-xm6x-46p6.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-crf2-xm6x-46p6
Aliases
Published
2020-08-19T18:02:36Z
Modified
2023-12-06T01:00:15.663771Z
Severity
  • 8.0 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N CVSS Calculator
Summary
Observable Timing Discrepancy in OpenMage LTS
Details

Impact

This vulnerability allows to circumvent the formkey protection in the Admin Interface and increases the attack surface for Cross Site Request Forgery attacks

Patches

The latest OpenMage Versions up from 19.4.6 and 20.0.2 have this Issue solved

References

Related to Adobes CVE-2020-9690 ( https://helpx.adobe.com/security/products/magento/apsb20-47.html ) fixed in Magento2 https://github.com/magento/magento2/commit/52d72b8010c9cecb5b8e3d98ec5edc1ddcc65fb4 as part of 2.4.0/2.3.5-p2

Database specific
{
    "nvd_published_at": "2020-08-20T01:17:00Z",
    "github_reviewed_at": "2020-08-19T18:02:10Z",
    "severity": "HIGH",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-203",
        "CWE-352"
    ]
}
References

Affected packages

Packagist / openmage/magento-lts

Package

Name
openmage/magento-lts
Purl
pkg:composer/openmage/magento-lts

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
19.4.6

Affected versions

1.*

1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1

v19.*

v19.4.0
v19.4.1
v19.4.2
v19.4.3
v19.4.4
v19.4.5

Packagist / openmage/magento-lts

Package

Name
openmage/magento-lts
Purl
pkg:composer/openmage/magento-lts

Affected ranges

Type
ECOSYSTEM
Events
Introduced
20.0.0
Fixed
20.0.2

Affected versions

v20.*

v20.0.0
v20.0.1