Magento 2.3 : Update critical vulnerability website from host request
Budget: $10 – $30 USD
Please find below the mail sent by my host provider.
You are using Magento Open Source hosted on this server 163.172.111.64 which according to a government organization is affected by a critical vulnerability.
They allow an unauthenticated attacker to execute arbitrary code remotely on the vulnerable server.
The publisher indicates that the identified vulnerability CVE-2022-24086 is exploited in the context of targeted attacks.
References :
Some listed Magento services expose their version number. The action of hiding this information will not stop the identification of the product, it will however provide a first level of security in order to avoid a compromise by means of automated exploitation tools.
- Multiple vulnerabilities in Adobe Commerce – CERT-FR (ssi.gouv.fr)<https://cert.ssi.gouv.fr/avis/CERTFR-2022-AVI-167/>
- News bulletin CERTFR-2022-ACT-007 – CERT-FR (ssi.gouv.fr)<https://www.cert.ssi.gouv.fr/actualite/CERTFR-2022-ACT-007/>
- https://github.com/Mr-xn/CVE-2022-24086
- https://www.atwix.com/magento-2/hide-version/
We invite you to apply the corrective measures quickly in order to resolve the problem.
Thanking you in advance.
Kind regards,
Scaleway Abuse Team
You are using Magento Open Source hosted on this server 163.172.111.64 which according to a government organization is affected by a critical vulnerability.
They allow an unauthenticated attacker to execute arbitrary code remotely on the vulnerable server.
The publisher indicates that the identified vulnerability CVE-2022-24086 is exploited in the context of targeted attacks.
References :
Some listed Magento services expose their version number. The action of hiding this information will not stop the identification of the product, it will however provide a first level of security in order to avoid a compromise by means of automated exploitation tools.
- Multiple vulnerabilities in Adobe Commerce – CERT-FR (ssi.gouv.fr)<https://cert.ssi.gouv.fr/avis/CERTFR-2022-AVI-167/>
- News bulletin CERTFR-2022-ACT-007 – CERT-FR (ssi.gouv.fr)<https://www.cert.ssi.gouv.fr/actualite/CERTFR-2022-ACT-007/>
- https://github.com/Mr-xn/CVE-2022-24086
- https://www.atwix.com/magento-2/hide-version/
We invite you to apply the corrective measures quickly in order to resolve the problem.
Thanking you in advance.
Kind regards,
Scaleway Abuse Team