{"api_version":"1","generated_at":"2026-07-23T13:18:12+00:00","cve":"CVE-2019-7950","urls":{"html":"https://cve.report/CVE-2019-7950","api":"https://cve.report/api/cve/CVE-2019-7950.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-7950","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-7950"},"summary":{"title":"CVE-2019-7950","description":"An access control bypass vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An unauthenticated user can bypass access controls via REST API calls to assign themselves to an arbitrary company, thereby gaining read access to potentially confidental information.","state":"PUBLIC","assigner":"psirt@adobe.com","published_at":"2019-08-02 22:15:00","updated_at":"2020-08-24 17:37:00"},"problem_types":["CWE-639"],"metrics":[],"references":[{"url":"https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-13","name":"https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-13","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Magento 2.3.2, 2.2.9 and 2.1.18 Security Update 1/3 | Magento","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-7950","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-7950","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"7950","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"magento","cpe5":"magento","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"open_source","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"7950","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"magento","cpe5":"magento","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"open_source","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-7950","ASSIGNER":"psirt@adobe.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"Magento 2","version":{"version_data":[{"version_value":"Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Access Control Bypass"}]}]},"references":{"reference_data":[{"refsource":"CONFIRM","name":"https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-13","url":"https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-13"}]},"description":{"description_data":[{"lang":"eng","value":"An access control bypass vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An unauthenticated user can bypass access controls via REST API calls to assign themselves to an arbitrary company, thereby gaining read access to potentially confidental information."}]}},"nvd":{"publishedDate":"2019-08-02 22:15:00","lastModifiedDate":"2020-08-24 17:37:00","problem_types":["CWE-639"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*","versionStartIncluding":"2.1.0","versionEndExcluding":"2.1.18","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*","versionStartIncluding":"2.2.0","versionEndExcluding":"2.2.9","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*","versionStartIncluding":"2.3.0","versionEndExcluding":"2.3.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"7950","Ordinal":"145783","Title":"CVE-2019-7950","CVE":"CVE-2019-7950","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"7950","Ordinal":"1","NoteData":"An access control bypass vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An unauthenticated user can bypass access controls via REST API calls to assign themselves to an arbitrary company, thereby gaining read access to potentially confidental information.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"7950","Ordinal":"2","NoteData":"2019-08-02","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"7950","Ordinal":"3","NoteData":"2019-08-02","Type":"Other","Title":"Modified"}]}}}