Lucene search

K
osvGoogleOSV:GHSA-9WC9-498W-H8XV
HistoryMay 24, 2022 - 5:07 p.m.

Magento deserialization vulnerability

2022-05-2417:07:42
Google
osv.dev
8
magento
deserialization
vulnerability
arbitrary code execution
untrusted data

AI Score

7.5

Confidence

Low

EPSS

0.006

Percentile

78.3%

Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.

AI Score

7.5

Confidence

Low

EPSS

0.006

Percentile

78.3%