{"id":"GHSA-crf2-xm6x-46p6","summary":"Observable Timing Discrepancy in OpenMage LTS","details":"### Impact\nThis vulnerability allows to circumvent the **formkey protection** in the Admin Interface and increases the attack surface for  **Cross Site Request Forgery** attacks \n\n### Patches\nThe latest OpenMage Versions up from 19.4.6 and 20.0.2 have this Issue solved\n\n\n### References\nRelated to Adobes CVE-2020-9690 ( https://helpx.adobe.com/security/products/magento/apsb20-47.html )\nfixed in Magento2 https://github.com/magento/magento2/commit/52d72b8010c9cecb5b8e3d98ec5edc1ddcc65fb4\nas part of 2.4.0/2.3.5-p2","aliases":["BIT-magento-2020-15151","CVE-2020-15151"],"modified":"2026-07-08T05:59:57.116725687Z","published":"2020-08-19T18:02:36Z","database_specific":{"github_reviewed_at":"2020-08-19T18:02:10Z","nvd_published_at":"2020-08-20T01:17:00Z","cwe_ids":["CWE-203","CWE-352"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/OpenMage/magento-lts/security/advisories/GHSA-crf2-xm6x-46p6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-15151"},{"type":"WEB","url":"https://github.com/OpenMage/magento-lts/commit/7c526bc6a6a51b57a1bab4c60f104dc36cde347a"},{"type":"PACKAGE","url":"https://github.com/OpenMage/magento-lts"},{"type":"WEB","url":"https://helpx.adobe.com/security/products/magento/apsb20-47.html"}],"affected":[{"package":{"name":"openmage/magento-lts","ecosystem":"Packagist","purl":"pkg:composer/openmage/magento-lts"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"19.4.6"}]}],"versions":["1.9.1.1","1.9.2.0","1.9.2.1","1.9.2.2","1.9.2.3","1.9.2.4","1.9.3.0","1.9.3.1","v19.4.0","v19.4.1","v19.4.2","v19.4.3","v19.4.4","v19.4.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/08/GHSA-crf2-xm6x-46p6/GHSA-crf2-xm6x-46p6.json"}},{"package":{"name":"openmage/magento-lts","ecosystem":"Packagist","purl":"pkg:composer/openmage/magento-lts"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"20.0.0"},{"fixed":"20.0.2"}]}],"versions":["v20.0.0","v20.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/08/GHSA-crf2-xm6x-46p6/GHSA-crf2-xm6x-46p6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N"}]}