VYPR

Bitnami package

magento

pkg:bitnami/magento

Vulnerabilities (96)

  • CVE-2020-9591Jun 26, 2020
    affected >= 2.2.0, < 2.2.12fixed 2.2.12

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth security mitigation vulnerability. Successful exploitation could lead to unauthorized access to admin panel.

  • CVE-2020-9632Jun 26, 2020
    affected >= 2.2.0, < 2.2.12fixed 2.2.12

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-9580Jun 26, 2020
    affected >= 2.2.0, < 2.2.12fixed 2.2.12

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-9581Jun 26, 2020
    affected >= 2.2.0, < 2.2.12fixed 2.2.12

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

  • CVE-2020-9582Jun 26, 2020
    affected >= 2.2.0, < 2.2.12fixed 2.2.12

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-9583Jun 26, 2020
    affected >= 2.2.0, < 2.2.12fixed 2.2.12

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-9587Jun 26, 2020
    affected >= 2.2.0, < 2.2.12fixed 2.2.12

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an authorization bypass vulnerability. Successful exploitation could lead to potentially unauthorized product discounts.

  • CVE-2020-9584Jun 26, 2020
    affected >= 2.2.0, < 2.2.12fixed 2.2.12

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

  • CVE-2020-9579Jun 26, 2020
    affected >= 2.2.0, < 2.2.12fixed 2.2.12

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-9585Jun 26, 2020
    affected >= 2.2.0, < 2.2.12fixed 2.2.12

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth security mitigation vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-3758Jan 29, 2020
    affected >= 2.2.0, < 2.2.11fixed 2.2.11

    Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

  • CVE-2020-3719Jan 29, 2020
    affected >= 2.2.0, < 2.2.11fixed 2.2.11

    Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have an sql injection vulnerability. Successful exploitation could lead to sensitive information disclosure.

  • CVE-2020-3718Jan 29, 2020
    affected >= 2.2.0, < 2.2.11fixed 2.2.11

    Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-3717Jan 29, 2020
    affected >= 2.2.0, < 2.2.11fixed 2.2.11

    Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a path traversal vulnerability. Successful exploitation could lead to sensitive information disclosure.

  • CVE-2020-3716Jan 29, 2020
    affected >= 2.2.0, < 2.2.11fixed 2.2.11

    Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-3715Jan 29, 2020
    affected >= 2.2.0, < 2.2.11fixed 2.2.11

    Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

Page 5 of 5