Information Exposure Through Timing Discrepancy in Adobe Commerce (formerly Magento Commerce) and Magento Open Source - CVE-2020-9690
Published: July 29, 2020
Vulnerability identifier: #VU32884
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-9690
CWE-ID: CWE-208
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to the an exploitable timing discrepancy issue. A remote administrator can disclose sensitive information on the target system, leading to signature verification bypass.
Affected software
Adobe Commerce (formerly Magento Commerce)
Magento Open Source
Magento Open Source
How to mitigate CVE-2020-9690
Install updates from vendor's website.
Adobe Commerce (formerly Magento Commerce) - addressed in versions 2.3.5-p2, 2.4.0
Magento Open Source - addressed in versions 2.3.5-p2, 2.4.0
Magento Open Source - addressed in versions 2.3.5-p2, 2.4.0