Description
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Dependency injection through Symphony framework allows service identifiers to be derived from user controlled data, which can lead to remote code execution.
Remediation
References
Related Vulnerabilities
MediaWiki Insertion of Sensitive Information into Log File Vulnerability (CVE-2024-40598)
Oracle JRE CVE-2014-0459 Vulnerability (CVE-2014-0459)
IBM RTC Cross-site Scripting (XSS) Vulnerability (CVE-2020-4691)
Apache HTTP Server Other Vulnerability (CVE-2003-0189)
WordPress Plugin Plainview Activity Monitor Remote Command Execution (20161228)