CVE-2020-9690
29.07.2020, 13:15
Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have an observable timing discrepancy vulnerability. Successful exploitation could lead to signature verification bypass.Enginsight
Vendor | Product | Version |
---|---|---|
magento | magento | 𝑥 < 2.3.5 |
magento | magento | 𝑥 < 2.3.5 |
magento | magento | 2.3.5 |
magento | magento | 2.3.5 |
magento | magento | 2.3.5:p1 |
magento | magento | 2.3.5:p1 |
𝑥
= Vulnerable software versions