Skip to content

Information disclosure through processing of external XML entities

Moderate severity GitHub Reviewed Published Nov 12, 2019 to the GitHub Advisory Database • Updated Feb 12, 2024

Package

composer magento/community-edition (Composer)

Affected versions

>= 2.2, < 2.2.10
>= 2.3, < 2.3.2-p2

Patched versions

2.2.10
2.3.2-p2

Description

An XML entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can craft document type definition for an XML representing XML layout. The crafted document type definition and XML layout allow processing of external entities which can lead to information disclosure.

As per the Magento Release 2.3.3, if you have already implemented the pre-release version of this patch (2.3.2-p1), it is highly recommended to promptly upgrade to 2.3.2-p2.

References

Published by the National Vulnerability Database Nov 5, 2019
Reviewed Nov 12, 2019
Published to the GitHub Advisory Database Nov 12, 2019
Last updated Feb 12, 2024

Severity

Moderate
4.9
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
High
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CVE ID

CVE-2019-8126

GHSA ID

GHSA-427g-2r83-3ccm

Source code

No known source code
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.