Magento Magento 2.3.7 Patch 1 Open Source Edition

CPE Details

Magento Magento 2.3.7 Patch 1 Open Source Edition
2.3.7
2022-10-21
15h51 +00:00
2022-10-21
19h03 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:magento:magento:2.3.7:p1:*:*:open_source:*:*:*

Informations

Vendor

magento

Product

magento

Version

2.3.7

Update

p1

Software Edition

open_source

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2022-42344 2022-10-20 16h28 +00:00 Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Incorrect Authorization vulnerability. An authenticated attacker can exploit this vulnerability to achieve information exposure and privilege escalation.
8.8
Haute
CVE-2021-28567 2021-09-08 16h19 +00:00 Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Improper Authorization vulnerability in the customers module. Successful exploitation could allow a low-privileged user to modify customer data. Access to the admin console is required for successful exploitation.
6.5
Moyen
CVE-2021-28566 2021-09-08 16h19 +00:00 Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Information Disclosure vulnerability when uploading a modified png file to a product image. Successful exploitation could lead to the disclosure of document root path by an unauthenticated attacker. Access to the admin console is required for successful exploitation.
3.7
Bas