CVE-2019-8121
Using JS libraries with known security vulnerabilities
EPSS 0.18%
Description
An insecure component vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. Magento 2 codebase leveraged outdated versions of JS libraries (Bootstrap, jquery, Knockout) with known security vulnerabilities.
How to fix CVE-2019-8121
To remediate CVE-2019-8121, upgrade the affected package to a fixed version below.
- Packagist/magento/community-edition—upgrade to 2.2.10 or later
- Packagist/magento/product-community-edition—upgrade to 2.2.10 or later
Is CVE-2019-8121 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- >= 2.2, < 2.2.10
- >= 2.2, < 2.2.10