Allele Security Alert
ASA-2019-00185
Identifier(s)
ASA-2019-00185, PRODSECBUG-2162
Title
Unauthorized data control due to a bypass of authentication controls for a customer using a web API endpoint
Vendor(s)
Magento
Product(s)
Magento
Affected version(s)
Magento 2.1 prior to 2.1.17
Magento 2.2 prior to 2.2.8
Magento 2.3 prior to 2.3.1
Fixed version(s)
Magento 2.1.17
Magento 2.2.8
Magento 2.3.1
Proof of concept
Unknown
Description
An authenticated customer can control other customer’s requisition lists by using a web API endpoint to send a request to the server. (This overrides the customer_id parameter)
Technical details
Unknown
Credits
Brian LaBelle
Reference(s)
Magento 2.3.1, 2.2.8 and 2.1.17 Security Update
https://magento.com/security/patches/magento-2.3.1-2.2.8-and-2.1.17-security-update
If there is any error in this alert or you wish a comprehensive analysis, let us know.
Last modified: April 17, 2019