Updates released by Adobe on Tuesday for the Magento Commerce and Open Source editions address multiple critical severity vulnerabilities that could lead to arbitrary code execution.
A total of six critical vulnerabilities were patched in the popular e-commerce platform, none of which requires authentication for a successful exploitation. All of them could be exploited to execute code on vulnerable systems.
These vulnerabilities include four command injection bugs (tracked as CVE-2020-9576, CVE-2020-9578, CVE-2020-9582, and CVE-2020-9583), and two security mitigation bypass flaws (tracked as CVE-2020-9579 and CVE-2020-9580).
The new Magento updates also include patches for four vulnerabilities considered important. Three of these (CVE-2020-9577, CVE-2020-9581, and CVE-2020-9584) are stored Cross-Site Scripting (XSS) flaws leading to sensitive information disclosure, while the fourth (CVE-2020-9588) is an Observable Timing Discrepancy bug leading to signature verification bypass.
Additionally, Adobe released patches for three moderate severity vulnerabilities. These include two defense-in-depth security mitigation issues (CVE-2020-9585 and CVE-2020-9591) that could lead to code execution and unauthorized access to the admin panel, respectively, and an authorization bypass issue (CVE-2020-9587) leading to potentially unauthorized product discounts.
The bugs were addressed with the release of Magento Commerce and Magento Open Source 2.3.4-p2 and 2.3.5-p1, Magento Enterprise Edition 1.14.4.5, and Magento Community Edition 1.9.4.5.
This week, Adobe also released patches for vulnerabilities in Bridge and Illustrator products, including many that have a critical severity rating.
Related: Adobe Patches 22 Vulnerabilities in Bridge, Illustrator
Related: Magento 2.3.4 Patches Critical Code Execution Vulnerabilities
Related: Hackers Accessed Magento Marketplace User Data

More from Ionut Arghire
- Google Workspace Gets Passkey Authentication
- Cybersecurity Startup Elba Raises €2.5 Million for Employee-Focused Product
- Apple Unveils Upcoming Privacy and Security Features
- Dozens of Malicious Extensions Found in Chrome Web Store
- Microsoft Makes SMB Signing Default Requirement in Windows 11 to Boost Security
- Zyxel Urges Customers to Patch Firewalls Against Exploited Vulnerabilities
- Gigabyte Rolls Out BIOS Updates to Remove Backdoor From Motherboards
- Information of 2.5M People Stolen in Ransomware Attack at Massachusetts Health Insurer
Latest News
- Keep Aware Raises $2.4M to Eliminate Browser Blind Spots
- Google Workspace Gets Passkey Authentication
- Cybersecurity Startup Elba Raises €2.5 Million for Employee-Focused Product
- Zoom Expands Privacy Options for European Customers
- Several Major Organizations Confirm Being Impacted by MOVEit Attack
- Apple Unveils Upcoming Privacy and Security Features
- Verizon 2023 DBIR: Human Error Involved in Many Breaches, Ransomware Cost Surges
- Google Patches Third Chrome Zero-Day of 2023
