GHSA-x5q5-6wvf-2fpq
Dashboard / Vulnerabilities / GHSA-x5q5-6wvf-2fpq
Summary: Magento 2 Community Edition Insufficient Logging
Details: An insufficient logging and monitoring vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. Failure to track admin actions related to design configuration could lead to repudiation attacks.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-8124, https://github.com/FriendsOfPHP/security-advisories/blob/master/magento/product-community-edition/CVE-2019-8124.yaml, https://github.com/magento/magento2, https://magento.com/security/patches/magento-2.3.3-and-2.2.10-security-update, https://web.archive.org/web/20220121051105/https://magento.com/security/patches/magento-2.3.3-and-2.2.10-security-update
Affected packages
Package
Name: magento/community-edition
Purl: pkg:composer/magento/community-edition
Affected ranges
Type: ECOSYSTEM
Events:
