{ "schema_version": "1.4.0", "id": "GHSA-cv25-3pxr-4q7x", "modified": "2024-05-15T22:34:06Z", "published": "2024-05-15T22:34:06Z", "aliases": [], "summary": "Magento Open Source Security Advisory: Patch SUPEE-10975", "details": "Magento Commerce 1.14.4.0 and Open Source 1.9.4.0 have been enhanced with critical security updates to address multiple vulnerabilities, including remote code execution (RCE), cross-site scripting (XSS), cross-site request forgery (CSRF), and more. The following issues have been identified and remediated:\n\n- PRODSECBUG-1589: Stops Brute Force Requests via basic RSS authentication\n- MAG-23: M1 Credit Card Storage Capability\n- PRODSECBUG-2149: Authenticated RCE using customer import\n- PRODSECBUG-2159: API Based RCE Vulnerability\n- PRODSECBUG-2156: RCE Via Unauthorized Upload\n- PRODSECBUG-2155: Authenticated RCE using dataflow\n- PRODSECBUG-2053: Prevents XSS in Newsletter Template\n- PRODSECBUG-2142: XSS in CMS Preview\n- PRODSECBUG-1860: Admin Account XSS Attack Cessation via Filename\n- PRODSECBUG-2119: EE Patch to include names in templates\n- PRODSECBUG-2129: XSS in Google Analytics Vulnerability\n- PRODSECBUG-2019: Merchant Wishlist Security Strengthening\n- PRODSECBUG-2104: Send to a Friend Vulnerability\n- PRODSECBUG-2125: CSRF on deletion of Blocks Vulnerability\n- PRODSECBUG-2088: CSRF Vulnerability related to Customer Group Deletion\n- PRODSECBUG-2140: CSRF on deletion of Site Map\n- PRODSECBUG-2108: Outdated jQuery causing PCI scanning failures\n- MAG-12, MAG-2: Encryption Keys Stored in Plain Text\n- PRODSECBUG-2141: Unauthorized Admin Panel Bypass\n\n### Patching and Upgrading:\nPatches and upgrades are available for the following Magento versions:\n\nMagento Commerce 1.9.0.0-1.14.4.0: Apply SUPEE-10975 or upgrade to Magento Commerce 1.14.4.0.\nMagento Open Source 1.5.0.0-1.9.4.0: Apply SUPEE-10975 or upgrade to Magento Open Source 1.9.4.0.", "severity": [], "affected": [ { "package": { "ecosystem": "Packagist", "name": "magento/community-edition" }, "ranges": [ { "type": "ECOSYSTEM", "events": [ { "introduced": "1.9.0.0" }, { "fixed": "1.14.4.0" } ] } ] } ], "references": [ { "type": "WEB", "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/magento/magento1ee/2018-11-28.yaml" }, { "type": "PACKAGE", "url": "https://github.com/magento/magento2" }, { "type": "WEB", "url": "https://magento.com/security/patches/supee-10975" }, { "type": "WEB", "url": "https://web.archive.org/web/20210517140123/https://magento.com/security/patches/supee-10975" } ], "database_specific": { "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2024-05-15T22:34:06Z", "nvd_published_at": null } }