2017
20.09
Magento – Critical security issues closed

The developer of the eCommerce software Magento has released updates and patches for Magento Commerce and Open Source, which include several, sometimes classified as critical security gaps. Users of the Magento Commerce versions 1.9.0.0 to 1.14.3.4 including the manufacturer recommends an update to version 1.14.3.6. Magento open source users of versions from 1.5.0.0 up to and including 1.9.3.4 should switch to 1.9.3.6. A patch (SUPEE-10266) is also available for both user groups, which must close gaps in all older versions, but must be entered manually.

The updates and patches protect against remote code execution, cross-site scripting and information leaks. Also in the Magento 2er family there are new releases in the form of the commerce and open-source versions 2.0.16 and 2.1.9, which also fix several vulnerabilities.

Patches for Magento 1
Patches for Magento 2

back