GHSA-653q-vqm6-gmjm
Dashboard / Vulnerabilities / GHSA-653q-vqm6-gmjm
Summary: Magento 2 Community Edition Arbitrary File Deletion
Details: An arbitrary file deletion vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated users can manipulate the design layout update feature.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-8090, https://github.com/FriendsOfPHP/security-advisories/blob/master/magento/product-community-edition/CVE-2019-8090.yaml, https://github.com/magento/magento2, https://magento.com/security/patches/magento-2.3.3-and-2.2.10-security-update, https://web.archive.org/web/20220121051105/https://magento.com/security/patches/magento-2.3.3-and-2.2.10-security-update
Affected packages
Package
Name: magento/community-edition
Purl: pkg:composer/magento/community-edition
Affected ranges
Type: ECOSYSTEM
Events:
