GHSA-2fhr-f6q6-c4p2
Dashboard / Vulnerabilities / GHSA-2fhr-f6q6-c4p2
Summary: Magento 2 Community Edition Access Control Bypass
Details: An access control bypass vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An unauthenticated user can bypass access controls via REST API calls to assign themselves to an arbitrary company, thereby gaining read access to potentially confidental information.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-7950, https://github.com/FriendsOfPHP/security-advisories/blob/master/magento/product-community-edition/CVE-2019-7950.yaml, https://github.com/magento/magento2, https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-13, https://web.archive.org/web/20211206084839/https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-13
Affected packages
Package
Name: magento/community-edition
Purl: pkg:composer/magento/community-edition
Affected ranges
Type: ECOSYSTEM
Events:
