Published: September 25, 2020
Last updated:

APSB20-47 (CVE-2020-9690) patch for Magento 1.x

Magento 1.x versions have observable timing discrepancy vulnerability (CVE-2020-9690). Successful exploitation could lead to signature verification bypass. This vulnerability allows to circumvent the formkey protection in the Admin Interface and increases the attack surface for Cross Site Request Forgery attacks.

The vulnerability is fixed in APSB20-47 patch for M1.x adopted from corresponding patch for Magento2 versions. OpenMage v19.4.6 and 20.0.2 have this vulnerability fixed as well.

Solution

Upgrade to OpenMage v19.4.6 or install this patch for M1.x to protect your store from this vulnerability.

Magento versionSUPEE-APSB20-47MD5 checksum
Magento CE 1.9.4.0-1.9.4.5SUPEE-11346 1.9.4.58be29901c03e24337969a0e6ed3e1c09
OpenMage v19.4.3upgrade to v19.4.6 or newer
OpenMage v19.4.6the patch is already included


2 votes, 5.00 avg. rating (90% score)