Description
A security bypass vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. A user with privileges to generate sitemaps can bypass configuration that restricts directory access. The bypass allows overwrite of a subset of configuration files which can lead to denial of service.
Remediation
References
Related Vulnerabilities
WordPress 4.4.x Directory Traversal (4.4 - 4.4.32)
Jetty CVE-2018-12536 Vulnerability (CVE-2018-12536)
WordPress Plugin Ultimate Profile Builder By CMSHelpLive Multiple Vulnerabilities (2.3.3)
SharePoint CVE-2020-16941 Vulnerability (CVE-2020-16941)
Oracle HTTP Server CVE-2020-2545 Vulnerability (CVE-2020-2545)