ืงืจื™ื˜ื™ืฉ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ ื“ื™ Magento E- ื”ืึทื ื“ืœ ืคึผืœืึทื˜ืคืึธืจืžืข

ืึทื“ืึธื•ื‘ื™ ืคึฟื™ืจืžืข ื‘ืืคืจื™ื™ื˜ ืึทืคึผื“ื™ื™ื˜ื™ื ื’ ืึทืŸ ืึธืคึฟืŸ ืคึผืœืึทื˜ืคืึธืจืžืข ืคึฟืึทืจ ืึธืจื’ืึทื ื™ื™ื–ื™ื ื’ E- ื”ืึทื ื“ืœ ืžืึทื’ืขื ื˜ืึธ (2.3.4, 2.3.3-ืคึผ1 ืื•ืŸ 2.2.11), ื•ื•ืึธืก ื ืขืžื˜ ื•ื•ืขื’ืŸ ืงืกื ื•ืžืงืก% ืžืึทืจืง ืคื•ืŸ ืกื™ืกื˜ืขืžืขืŸ ืคึฟืึทืจ ืงืจื™ื™ื™ื˜ื™ื ื’ ืึธื ืœื™ื™ืŸ ืกื˜ืึธืจื– (ืึทื“ืึธื‘ืข ืื™ื– ื’ืขื•ื•ืืจืŸ ื“ื™ ื‘ืึทื–ื™ืฆืขืจ ืคื•ืŸ Magento ืื™ืŸ 2018). ื“ืขืจ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ ื™ืœื™ืžืึทื ื™ื™ืฅ 6 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–, ืคื•ืŸ ื•ื•ืึธืก ื“ืจื™ื™ ื–ืขื ืขืŸ ืึทืกื™ื™ื ื“ ืึท ืงืจื™ื˜ื™ืฉ ืžื“ืจื’ื” ืคื•ืŸ ื’ืขืคืึทืจ (ืคืจื˜ื™ื ื–ืขื ืขืŸ ื ืึธืš ื ื™ืฉื˜ ืžื•ื“ื™ืข):

  • CVE-2020-3716 - ื“ื™ ืžืขื’ืœืขื›ืงื™ื™ื˜ ืคื•ืŸ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืคื•ืŸ ืึทื˜ืึทืงืขืจ ืงืึธื“ ื•ื•ืขืŸ ื“ื™ืกืขืจื™ืึทืœื™ื–ื™ื ื’ ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ื“ืึทื˜ืŸ;
  • CVE-2020-3718 - ื‘ื™ื™ืคึผืึทืก ืคื•ืŸ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžืขืงืึทื ื™ื–ืึทืžื– ื•ื•ืึธืก ืคื™ืจืŸ ืฆื• ื“ืขืจ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืคื•ืŸ ืึทืจื‘ื™ื˜ืจืึทืจื™ืฉ ืงืึธื“ ืื•ื™ืฃ ื“ื™ ืกืขืจื•ื•ืขืจ ื–ื™ื™ึทื˜;
  • CVE-2020-3719 ืื™ื– ืึท SQL ื‘ืึทืคึฟืขืœ ืกืึทื‘ืกื˜ื™ื˜ื•ืฉืึทืŸ ืฉื˜ืจื™ืš ื•ื•ืึธืก ืึทืœืึทื•ื– ืึทืงืกืขืก ืฆื• ื“ืึทื˜ืŸ ืื™ืŸ ื“ื™ ื“ืึทื˜ืึทื‘ื™ื™ืก.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’