Description
A security bypass vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. A user with privileges to generate sitemaps can bypass configuration that restricts directory access. The bypass allows overwrite of a subset of configuration files which can lead to denial of service.
Remediation
References
Related Vulnerabilities
Oracle Application Server Other Vulnerability (CVE-2007-0284)
WordPress Plugin Modern Events Calendar Lite Cross-Site Scripting (5.22.1)
Plone CMS Missing Authentication for Critical Function Vulnerability (CVE-2020-35190)
Apache Traffic Server Improper Input Validation Vulnerability (CVE-2021-37150)