Description
An insecure component vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Magento 2 codebase leveraged outdated versions of HTTP specification abstraction implemented in symphony component.
Remediation
References
Related Vulnerabilities
WordPress Plugin Royal Elementor Addons and Templates Arbitrary File Upload (1.3.78)
WordPress Plugin Light Post 'abspath' Parameter Remote File Include (1.4)
WordPress Plugin Newsletters Cross-Site Scripting (4.6.18)
Drupal Core 7.x Security Bypass (7.0 - 7.2)
Internet Information Services Other Vulnerability (CVE-2001-0004)