-

   rss_rss_hh_new

 - e-mail

 

 -

 LiveInternet.ru:
: 17.03.2011
:
:
: 51

:


Magento, , ,

, 15 2017 . 22:07 +
kirmorozov 22:07

Magento, , ,

    image

    Magento 2.1.9, 2.0.16, XSS, CSRF, , / .
    Magento 1.x, 1.9.3.6 1.14.3.6 .

    / .
    : .

    (1)


    APPSEC-1800: Remote Code Execution vulnerability in CMS and layouts
    : , .
    layout, .
    - Magento 1.x , .
    - - .

    (3)


    APPSEC-1887 , .
    APPSEC-1850 - ,
    APPSEC-1851 RCE , .

    (29)


    APPSEC-1567 , -, cookie.
    APPSEC-1769 sitemap
    APPSEC-1713
    APPSEC-1852 XSS CSRF XSS CSRF
    APPSEC-1482
    APPSEC-1502 XSS
    APPSEC-1494 XSS - xml xml.
    APPSEC-1793 CRE Nginx
    APPSEC-1819 ,
    APPSEC-1802 CSRF
    APPSEC-1493 XSS
    APPSEC-1755 CSRF
    APPSEC-1853 XSS CSRF
    APPSEC-1729 XSS
    APPSEC-1591 XSS
    APPSEC-1896 XSS
    APPSEC-1673 XSS SVG favicon
    APPSEC-1773 DoS ID
    APPSEC-1577 XSS
    APPSEC-1510 favicon
    APPSEC-1545 XSS
    APPSEC-1535 .
    APPSEC-1588
    APPSEC-1701 API
    APPSEC-1630
    APPSEC-1628
    APPSEC-1599 - -

    (2)


    APPSEC-1709
    APPSEC-1495


    , Magento 1.x.
    APPSEC-1793 ngin .
    APPSEC-1588 .
    , , .
    , , X, , X. , .
    X .
    , .


    18 35 , .


    -, .

    1. , .
    2. , .

    : https://magento.com/security/patches/magento-2016-and-219-security-update
    : 2.015-2.0.16 2.1.8-2.1.9

    : .
    Original source: habrahabr.ru (comments, light).

    https://habrahabr.ru/post/338052/

    :  

    : [1] []
     

    :
    : 

    : ( )

    :

      URL