CVE-2020-9690

MEDIUM4.2EPSS 0.47%

Magento observable timing discrepancy vulnerability

Published: 5/24/2022Modified: 2/16/2024
Also known as:GHSA-xgp9-j48h-jjf9BIT-magento-2020-9690

Description

Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have an observable timing discrepancy vulnerability. Successful exploitation could lead to signature verification bypass.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.2CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N

References (4)