Security Updates Available for Magento | APSB20-59
| Product | Version | Platform |
|---|---|---|
| Magento Commerce |
2.3.5-p1 and earlier versions |
All |
| Magento Commerce |
2.3.5-p2 and earlier versions |
All |
| Magento Commerce |
2.4.0 and earlier versions |
All |
| Magento Open Source |
2.3.5-p1 and earlier versions |
All |
| Magento Open Source |
2.3.5-p2 and earlier versions |
All |
| Magento Open Source |
2.4.0 and earlier versions |
All |
Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version.
| Product | Updated Version | Platform | Priority Rating | Release Notes |
| Magento Commerce |
2.4.1 |
All |
2 |
2.4.1 Commerce |
| Magento Open Source |
2.4.1 |
All |
2 |
2.4.1 Open Source |
| Magento Commerce |
2.3.6 |
All | 2 | 2.3.6 Commerce |
| Magento Open Source |
2.3.6 |
All | 2 | 2.3.6 Open Source |
Note
Pre-authentication: The vulnerability is exploitable without credentials.
Admin privileges required: The vulnerability is only exploitable by an attacker with administrative privileges.
Additional technical descriptions of the CVEs referenced in this document will be made available on MITRE and NVD sites.
| Dependency | Vulnerability Impact | Affected Versions |
| jQuery File Upload | Arbitrary code execution |
2.4.0 and earlier versions |
| TinyMCE | Arbitrary JavaScript execution | 2.4.0 and earlier versions |
Adobe would like to thank the following individuals for reporting the relevant issues and for working with Adobe to help protect our customers:
- Edgar Boda-Majer of Bugscale (CVE-2020-24408)
- Kien Hoang (CVE-2020-24402, CVE-2020-24401, CVE-2020-24404, CVE-2020-24405)
- Ihorsv (CVE-2020-24406)
- Malerisch (CVE-2020-24407)
- Dang Toan (CVE-2020-24403)
- Yonatan Offek (CVE-2020-24400)
