GHSA-mcfc-67vm-j568

Suggest an improvement
Source
https://github.com/advisories/GHSA-mcfc-67vm-j568
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-mcfc-67vm-j568/GHSA-mcfc-67vm-j568.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mcfc-67vm-j568
Published
2024-05-15T22:34:09Z
Modified
2024-11-29T05:38:24.775337Z
Summary
Magento Cross-Site Scripting (XSS) vulnerability
Details

Magento Commerce and Open Source 2.2.6 and 2.1.15 contain multiple security enhancements that help close Cross-Site Scripting (XSS) and other vulnerabilities.

Database specific
{
    "nvd_published_at": null,
    "cwe_ids": [],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-05-15T22:34:09Z"
}
References

Affected packages

Packagist / magento/community-edition

Package

Name
magento/community-edition
Purl
pkg:composer/magento/community-edition

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.1
Fixed
2.1.15

Affected versions

2.*

2.1.0-rc1
2.1.0-rc2
2.1.0-rc3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14

Packagist / magento/community-edition

Package

Name
magento/community-edition
Purl
pkg:composer/magento/community-edition

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.2
Fixed
2.2.6

Affected versions

2.*

2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5