Vulnerability Intelligence Report
CVE-2019-7139
An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data leakage. This issue is fixed in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.
Nuclei Template
CVSS Base Score
9.8
CRITICAL
EPSS Probability:17.44%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Magento | Magento Open Source | prior to 1.9.4.1 (affected) |
| Magento | Magento Commerce | prior to 1.14.4.1 (affected) |
| Magento | Magento | prior to 2.1.17 (affected), prior to 2.2.8 (affected), prior to 2.3.1 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Adobe Systems Incorporated · Vendor · USA |
| Reserved | 2019-01-28T00:00:00 |
| Published | 2019-04-10T17:07:20 |
| Patch Date | 2019-03-29 |
| Last Updated | 2024-08-04T20:38:33 |
Community Chatter & Buzz