Cov teeb meem tseem ceeb hauv Magento e-commerce platform

Adobe tuam txhab tso tawm hloov kho lub platform qhib rau kev teeb tsa e-lag luam Magento (2.3.4, 2.3.3-p1 thiab 2.2.11), uas yuav siv sij hawm txog 10% kev ua lag luam ntawm cov tshuab tsim cov khw muag khoom online (Adobe los ua tus tswv ntawm Magento hauv 2018). Qhov hloov tshiab tshem tawm 6 qhov tsis zoo, ntawm peb qhov raug muab rau theem tseem ceeb ntawm kev txaus ntshai (cov ntsiab lus tseem tsis tau tshaj tawm):

  • CVE-2020-3716 - muaj peev xwm ntawm attacker code tua thaum deserializing lwm cov ntaub ntawv;
  • CVE-2020-3718 - bypass ntawm kev ruaj ntseg mechanisms ua rau kev ua tiav ntawm arbitrary code ntawm lub server sab;
  • CVE-2020-3719 yog SQL hais kom hloov pauv feature uas tso cai rau kev nkag mus rau cov ntaub ntawv hauv database.

Tau qhov twg los: opennet.ru

Ntxiv ib saib