Magento 2.3 : Update critical vulnerability website from host request

Job ID: 33143574

Budget: $10 – $30 USD

Please find below the mail sent by my host provider.

You are using Magento Open Source hosted on this server 163.172.111.64 which according to a government organization is affected by a critical vulnerability.

They allow an unauthenticated attacker to execute arbitrary code remotely on the vulnerable server.
The publisher indicates that the identified vulnerability CVE-2022-24086 is exploited in the context of targeted attacks.

References :

Some listed Magento services expose their version number. The action of hiding this information will not stop the identification of the product, it will however provide a first level of security in order to avoid a compromise by means of automated exploitation tools.

- Multiple vulnerabilities in Adobe Commerce – CERT-FR (ssi.gouv.fr)<https://cert.ssi.gouv.fr/avis/CERTFR-2022-AVI-167/>

- News bulletin CERTFR-2022-ACT-007 – CERT-FR (ssi.gouv.fr)<https://www.cert.ssi.gouv.fr/actualite/CERTFR-2022-ACT-007/>

- https://github.com/Mr-xn/CVE-2022-24086

- https://www.atwix.com/magento-2/hide-version/

We invite you to apply the corrective measures quickly in order to resolve the problem.
Thanking you in advance.


Kind regards,
Scaleway Abuse Team
Related categories: Web Security CSS HTML Server Magento 2