GHSA-33cj-w75f-49m2
Dashboard / Vulnerabilities / GHSA-33cj-w75f-49m2
Summary: Magento 2 Community Edition Server-Side Request Forgery vulnerability
Details: A server-side request forgery (SSRF) vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with access to the admin panel to manipulate system configuration and execute arbitrary code.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-7911, https://github.com/FriendsOfPHP/security-advisories/blob/master/magento/magento1ce/CVE-2019-7911.yaml, https://github.com/FriendsOfPHP/security-advisories/blob/master/magento/magento1ee/CVE-2019-7911.yaml, https://github.com/FriendsOfPHP/security-advisories/blob/master/magento/product-community-edition/CVE-2019-7911.yaml, https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-13, https://web.archive.org/web/20211206084839/https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-13
Affected packages
Package
Name: magento/community-edition
Purl: pkg:composer/magento/community-edition
Affected ranges
Type: ECOSYSTEM
Events:
