CVE-2019-7139
Summary
| CVE | CVE-2019-7139 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-10 18:29:00 UTC |
| Updated | 2019-08-06 14:15:00 UTC |
| Description | An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data leakage. This issue is fixed in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Magento 2.2.0 <= 2.3.0 Unauthenticated SQLi | MISC | www.ambionics.io | Exploit, Third Party Advisory |
| Magento 2.3.2, 2.2.9 and 2.1.18 Security Update 1/3 | Magento | CONFIRM | magento.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.