Bofokoli bo boholo sethaleng sa e-commerce sa Magento

Khamphani ea Adobe lokollotsoe ho nchafatsa sethala se bulehileng sa ho hlophisa khoebo ea e-commerce go magento (2.3.4, 2.3.3-p1 le 2.2.11), e nkang hoo e ka bang 10% 'maraka oa litsamaiso tsa ho theha mabenkele a marang-rang (Adobe e ile ea e-ba mong'a Magento ka 2018). Ntlafatso e felisa bofokoli ba 6, bao ba bararo ba bona ba abetsoeng boemo bo boima ba kotsi (lintlha ha li so phatlalatsoe):

  • CVE-2020-3716 - monyetla oa ho sebelisa khoutu ea bahlaseli ha o senya data ea kantle;
  • CVE-2020-3718 - bypass ea mekhoa ea ts'ireletso e lebisang ho kengoang khoutu e sa lebelloang ka lehlakoreng la seva;
  • CVE-2020-3719 ke karolo ea taelo ea SQL e lumellang phihlello ea data ho database.

Source: opennet.ru

Eketsa ka tlhaloso