152 lines
5.1 KiB
JSON
Raw Normal View History

2023-04-24 12:24:31 +02:00
{
"id": "CVE-2019-8090",
"sourceIdentifier": "psirt@adobe.com",
"published": "2019-11-05T22:15:14.080",
"lastModified": "2019-11-07T15:00:26.030",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "An arbitrary file deletion vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated users can manipulate the design layout update feature."
},
{
"lang": "es",
"value": "Existe una vulnerabilidad de eliminaci\u00f3n de archivos arbitrarios en Magento versiones 2.1 anteriores a la versi\u00f3n 2.1.19, Magento versiones 2.2 anteriores a la versi\u00f3n 2.2.10, Magento versiones 2.3 anteriores a la versi\u00f3n 2.3.3. Unos usuarios autenticados pueden manipular la funcionalidad design layout update."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 2.8,
"impactScore": 3.6
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "SINGLE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 5.5
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.0,
"impactScore": 4.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*",
"versionStartIncluding": "2.1.0",
"versionEndExcluding": "2.1.19",
"matchCriteriaId": "3878B059-069C-40C4-8A84-34A1F1997B5B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*",
"versionStartIncluding": "2.1.0",
"versionEndExcluding": "2.1.19",
"matchCriteriaId": "DE3E47A1-9FEA-465D-947A-DA33E410093F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*",
"versionStartIncluding": "2.2.0",
"versionEndExcluding": "2.2.10",
"matchCriteriaId": "24318637-C95B-4811-87F5-14A6F4EDE2EC"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*",
"versionStartIncluding": "2.2.0",
"versionEndExcluding": "2.2.10",
"matchCriteriaId": "A06CF88F-F067-4058-9306-864FEA3D7062"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*",
"versionStartIncluding": "2.3.0",
"versionEndExcluding": "2.3.2",
"matchCriteriaId": "B720D2FA-A6FD-49A3-8B78-07993560081D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*",
"versionStartIncluding": "2.3.0",
"versionEndExcluding": "2.3.2",
"matchCriteriaId": "6B8C5A27-2957-4373-B0FE-8C7585B4B04E"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:magento:magento:2.3.2:-:*:*:commerce:*:*:*",
"matchCriteriaId": "ED7EB5B4-33F4-4389-BCA4-50A113F8C719"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:magento:magento:2.3.2:-:*:*:open_source:*:*:*",
"matchCriteriaId": "465133F9-0BFE-491E-8FE8-A263F9E2FC1D"
}
]
}
]
}
],
"references": [
{
"url": "https://magento.com/security/patches/magento-2.3.3-and-2.2.10-security-update",
"source": "psirt@adobe.com",
"tags": [
"Patch",
"Vendor Advisory"
]
}
]
}