Skip to content
TURNKEYGNU / LINUX
AppsDocumentationBlogScreenshotsGitHubTurnKey Hub
文English
EnglishDeutschEspañol日本語Português中文
Home/Blog/TurnKey Magento NOT vulnerable to CVE-2016-4010 remote PHP code execution

From the project

TurnKey Magento NOT vulnerable to CVE-2016-4010 remote PHP code execution

By Jeremy DavisMay 27, 20161 min read
newssecuritymagento

Thanks to vondrt4 for bringing CVE-2016-4010 to our attention. This was a potentially critical vulnerability in Magento that turns out not to apply to TurnKey Magento, because it only effects Magento versions 2.0 - 2.0.5. The current version of TurnKey Magento is based on Magento 1.9.X.

Following our security procedure we first unpublished the vulnerable app from the library but after confirming it was not vulnerable we subsequently republished it and updated the documentation page to clarify the situation.

TurnKey users got lucky this time, but it's best not to rely on luck so we recommend that all Magento users sign up to the Magento Security Alerts in addition to the TurnKey Security and Announcements newsletter.

 

Comments (1)

really

Reply 1 2016-11-04

Thanks to vondrt4

Keep exploring

Find your next server

Browse ready-to-use appliances by the job you need to do.

Explore the app library
TURNKEYGNU / LINUX

Own your infrastructure without starting from scratch.

Explore TurnKey
AboutDocumentationFAQBlogGitHub
Free and open sourceSecure by defaultReady to deploy