Description
An insufficient logging and monitoring vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. Failure to track admin actions related to design configuration could lead to repudiation attacks.
Remediation
References
Related Vulnerabilities
WordPress 5.0.x Prototype Pollution (5.0 - 5.0.15)
WordPress Plugin FAQs Manager SQL Injection (1.0)
Nginx Out-of-bounds Write Vulnerability (CVE-2011-4315)
Internet Information Services Other Vulnerability (CVE-2006-6579)
GlassFish Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-3250)