ZeroHour

CVE-2020-9690

CVSS 3.1
4.2 medium
EPSS
2%p75
Published
()
Modified
Description

Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have an observable timing discrepancy vulnerability. Successful exploitation could lead to signature verification bypass.

Vendors
magento
Products
magento
Ecosystems
E-commerce
Weakness
CWE-203
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.