Magento Commerce and Open Source 2.2.1, 2.1.10 and 2.0.17 contain multiple security enhancements.
APPSEC-1325: Stored XSS in Billing Agreements
Type : Cross-Site Scripting (XSS, stored)
CVSSv3 Severity : 5.5 (Medium)
Known Attacks : None
Product(s)
Fixed In : Magento Open Source 1.9.3.7, Magento Commerce 1.14.3.7, SUPEE-10415, Magento 2.0.17, Magento 2.1.10, Magento 2.2.1
APPSEC-1825: PHP Object Injection in E-mail templates leading to Remote Code Execution
Type : Remote Code Execution (RCE)
CVSSv3 Severity : 8.2 (High)
Known Attacks : None
Description : An administrator with limited privileges can insert malicious code in e-mail templates, creating an opportunity for arbitrary remote code execution.
Product(s) Affected : Magento 2.0 prior to 2.0.17, Magento 2.1 prior to 2.1.10, Magento 2.2
Fixed In : Magento 2.0.17, Magento 2.1.10, Magento 2.2.1
APPSEC-1830: PHP Object Injection in product attributes leading to Remote Code Execution
Type : Remote Code Execution (RCE)
CVSSv3 Severity : 8.2 (High)
Known Attacks : None
Description : An administrator with limited privileges can insert injectable code in product attributes, potentially leading to arbitrary remote code execution.
Product(s)
Affected : Magento Open Source prior to 1.9.3.7, and Magento Commerce prior to 1.14.3.7, Magento 2.0 prior to 2.0.17, Magento 2.1 prior to 2.1.10, Magento 2.2
Fixed In : Magento Open Source 1.9.3.7, Magento Commerce 1.14.3.7, SUPEE-10415, Magento 2.0.17, Magento 2.1.10, Magento 2.2.1
APPSEC-1861: PHP Object Injection in product entries leading to Remote Code Execution
Type : Remote Code Execution (RCE)
CVSSv3 Severity : 8.2 (High)
Known Attacks : None
Description : An administrator with limited privileges can insert injectable code in promo fields, creating an opportunity for arbitrary remote code execution.
Product(s)
Affected : Magento Open Source prior to 1.9.3.7, and Magento Commerce prior to 1.14.3.7, Magento 2.0 prior to 2.0.17, Magento 2.1 prior to 2.1.10, Magento 2.2
Fixed In : Magento Open Source 1.9.3.7, Magento Commerce 1.14.3.7, SUPEE-10415, Magento 2.0.17, Magento 2.1.10, Magento 2.2.1
APPSEC-1881: PHP Object Injection in Downloadable Products leading to Remote Code Execution
Type : Remote Code Execution (RCE)
CVSSv3 Severity : 7.2 (High)
Known Attacks : None
Description : An administrator with limited privileges can create a downloadable product that can create an opportunity for arbitrary code execution.
Product(s) Affected: Magento 2.0 prior to 2.0.17, Magento 2.1 prior to 2.1.10, Magento 2.2
Fixed In : Magento 2.0.17, Magento 2.1.10, Magento 2.2.1
APPSEC-1893: PHP Object Injection in product metadata leading to Remote Code Execution
Type : Remote Code Execution (RCE)
CVSSv3 Severity : 8.2 (High)
Known Attacks : None
Description : An administrator with limited privileges can insert injectable code in the swatches feature, creating an opportunity for arbitrary remote code execution.
Product(s) Affected: Magento 2.0 prior to 2.0.17, Magento 2.1 prior to 2.1.10
Fixed In : Magento 2.0.17, Magento 2.1.10, Magento 2.2.1
APPSEC-1900: Remote Code Execution by leveraging 1st stage unsanitized form input
Type : Remote Code Execution (RCE)
CVSSv3 Severity : 8.2 (High)
Known Attacks : None
Description : An administrator with limited privileges can create a store website that can accept and run arbitrary remote code execution.
Product(s) Affected : Magento 2.0 prior to 2.0.17, Magento2.1 prior to2.1.10, Magento 2.2
Fixed In : Magento 2.0.17, Magento 2.1.10, Magento 2.2.1
APPSEC-1910: Local File Inclusion (LFI) in Import History
Type : Local File Inclusion + Potential RCE
CVSSv3 Severity : 6.1 (Medium)
Known Attacks : None
Description : An administrator with limited privileges can delete critical system control files to subsequently gain privilege escalation through the Import History section.
Product(s) Affected : Magento 2.0 prior to 2.0.17, Magento 2.1 prior to 2.1.10, Magento 2.2
Fixed In : Magento 2.0.17, Magento 2.1.10, Magento 2.2.1
APPSEC-1930: PHP Object Injection in Widgets leading to Remote Code Execution
Type : Remote Code Execution (RCE)
CVSSv3 Severity : 8.2 (High)
Known Attacks : None
Description : An administrator with limited privileges can insert a widget block containing malicious code, creating an opportunity for arbitrary remote code execution.
Product(s) Affected : Magento 2.0 prior to 2.0.17, Magento 2.1 prior to 2.1.10
Fixed In : Magento 2.0.17, Magento 2.1.10, Magento 2.2.1
APPSEC-1931 : PHP Object Injection in Zend Framework
leading to Arbitrary File Deletion
APPSEC-1931 : PHP Object Injection in Zend Framework leading to Arbitrary File Deletion
Type : Arbitrary File Delete
CVSSv3 Severity : 7.2 (High)
Known Attacks : None
Description : An administrator with limited privileges can inject malicious code that can cause sensitive files to be deleted. He could then launch a second stage payload that would lead to arbitrary remote code execution.
Product(s) Affected: Magento 2.0 prior to 2.0.17, Magento 2.1 prior to 2.1.10
Fixed In : Magento 2.0.17, Magento 2.1.10, Magento 2.2.1
- Cross-Site Scripting (XSS).
- Local File Inclusion (LFI).
- Authenticated Admin user remote code execution (RCE) .
- Arbitrary File Delete vulnerabilities
APPSEC-1325: Stored XSS in Billing Agreements
Type : Cross-Site Scripting (XSS, stored)
CVSSv3 Severity : 5.5 (Medium)
Known Attacks : None
Description : An administrator with limited privileges can create Billing Agreements with embedded cross-site scripting elements that can subsequently lead to a stored cross-site scripting attack.
Product(s)
Affected : Magento Open Source prior to 1.9.3.7, and Magento Commerce prior to 1.14.3.7, Magento 2.0 prior to 2.0.17, Magento 2.1 prior to 2.1.10, Magento 2.2
Fixed In : Magento Open Source 1.9.3.7, Magento Commerce 1.14.3.7, SUPEE-10415, Magento 2.0.17, Magento 2.1.10, Magento 2.2.1
APPSEC-1825: PHP Object Injection in E-mail templates leading to Remote Code Execution
Type : Remote Code Execution (RCE)
CVSSv3 Severity : 8.2 (High)
Known Attacks : None
Description : An administrator with limited privileges can insert malicious code in e-mail templates, creating an opportunity for arbitrary remote code execution.
Product(s) Affected : Magento 2.0 prior to 2.0.17, Magento 2.1 prior to 2.1.10, Magento 2.2
Fixed In : Magento 2.0.17, Magento 2.1.10, Magento 2.2.1
APPSEC-1830: PHP Object Injection in product attributes leading to Remote Code Execution
Type : Remote Code Execution (RCE)
CVSSv3 Severity : 8.2 (High)
Known Attacks : None
Description : An administrator with limited privileges can insert injectable code in product attributes, potentially leading to arbitrary remote code execution.
Product(s)
Affected : Magento Open Source prior to 1.9.3.7, and Magento Commerce prior to 1.14.3.7, Magento 2.0 prior to 2.0.17, Magento 2.1 prior to 2.1.10, Magento 2.2
Fixed In : Magento Open Source 1.9.3.7, Magento Commerce 1.14.3.7, SUPEE-10415, Magento 2.0.17, Magento 2.1.10, Magento 2.2.1
APPSEC-1861: PHP Object Injection in product entries leading to Remote Code Execution
Type : Remote Code Execution (RCE)
CVSSv3 Severity : 8.2 (High)
Known Attacks : None
Description : An administrator with limited privileges can insert injectable code in promo fields, creating an opportunity for arbitrary remote code execution.
Product(s)
Affected : Magento Open Source prior to 1.9.3.7, and Magento Commerce prior to 1.14.3.7, Magento 2.0 prior to 2.0.17, Magento 2.1 prior to 2.1.10, Magento 2.2
Fixed In : Magento Open Source 1.9.3.7, Magento Commerce 1.14.3.7, SUPEE-10415, Magento 2.0.17, Magento 2.1.10, Magento 2.2.1
APPSEC-1881: PHP Object Injection in Downloadable Products leading to Remote Code Execution
Type : Remote Code Execution (RCE)
CVSSv3 Severity : 7.2 (High)
Known Attacks : None
Description : An administrator with limited privileges can create a downloadable product that can create an opportunity for arbitrary code execution.
Product(s) Affected: Magento 2.0 prior to 2.0.17, Magento 2.1 prior to 2.1.10, Magento 2.2
Fixed In : Magento 2.0.17, Magento 2.1.10, Magento 2.2.1
APPSEC-1893: PHP Object Injection in product metadata leading to Remote Code Execution
Type : Remote Code Execution (RCE)
CVSSv3 Severity : 8.2 (High)
Known Attacks : None
Description : An administrator with limited privileges can insert injectable code in the swatches feature, creating an opportunity for arbitrary remote code execution.
Product(s) Affected: Magento 2.0 prior to 2.0.17, Magento 2.1 prior to 2.1.10
Fixed In : Magento 2.0.17, Magento 2.1.10, Magento 2.2.1
APPSEC-1900: Remote Code Execution by leveraging 1st stage unsanitized form input
Type : Remote Code Execution (RCE)
CVSSv3 Severity : 8.2 (High)
Known Attacks : None
Description : An administrator with limited privileges can create a store website that can accept and run arbitrary remote code execution.
Product(s) Affected : Magento 2.0 prior to 2.0.17, Magento2.1 prior to2.1.10, Magento 2.2
Fixed In : Magento 2.0.17, Magento 2.1.10, Magento 2.2.1
APPSEC-1910: Local File Inclusion (LFI) in Import History
Type : Local File Inclusion + Potential RCE
CVSSv3 Severity : 6.1 (Medium)
Known Attacks : None
Description : An administrator with limited privileges can delete critical system control files to subsequently gain privilege escalation through the Import History section.
Product(s) Affected : Magento 2.0 prior to 2.0.17, Magento 2.1 prior to 2.1.10, Magento 2.2
Fixed In : Magento 2.0.17, Magento 2.1.10, Magento 2.2.1
APPSEC-1930: PHP Object Injection in Widgets leading to Remote Code Execution
Type : Remote Code Execution (RCE)
CVSSv3 Severity : 8.2 (High)
Known Attacks : None
Description : An administrator with limited privileges can insert a widget block containing malicious code, creating an opportunity for arbitrary remote code execution.
Product(s) Affected : Magento 2.0 prior to 2.0.17, Magento 2.1 prior to 2.1.10
Fixed In : Magento 2.0.17, Magento 2.1.10, Magento 2.2.1
APPSEC-1931 : PHP Object Injection in Zend Framework
leading to Arbitrary File Deletion
APPSEC-1931 : PHP Object Injection in Zend Framework leading to Arbitrary File Deletion
Type : Arbitrary File Delete
CVSSv3 Severity : 7.2 (High)
Known Attacks : None
Description : An administrator with limited privileges can inject malicious code that can cause sensitive files to be deleted. He could then launch a second stage payload that would lead to arbitrary remote code execution.
Product(s) Affected: Magento 2.0 prior to 2.0.17, Magento 2.1 prior to 2.1.10
Fixed In : Magento 2.0.17, Magento 2.1.10, Magento 2.2.1
Thank you for sharing such useful information. I really enjoyed while reading your article and it is good to know the latest updates. Do post more. And also read about Magento 2 Development Company
ReplyDelete