VYPR
High severityNVD Advisory· Published Jun 26, 2020· Updated Aug 4, 2024

CVE-2020-9588

CVE-2020-9588

Description

Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an observable timing discrepancy vulnerability. Successful exploitation could lead to signature verification bypass.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
magento/community-editionPackagist
< 2.3.4-p22.3.4-p2
magento/corePackagist
< 1.9.4.51.9.4.5
magento/project-community-editionPackagist
<= 2.0.2

Affected products

1
  • Range: 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier versions

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.