Just a moment...

Magento Security Announcement – New Security Patch (SUPEE-6788)

Screen Shot 2015-10-27 at 7.01.56 PM

***Please note that this patch may interfere with certain Magento extensions and should be applied by your developer.***

 

Today, we are releasing a new security patch (SUPEE-6788), Enterprise Edition 1.14.2.2 and Community Edition 1.9.2.2 to address over 10 issues identified through our comprehensive security program, including remote code execution and information leak vulnerabilities. This patch is unrelated to the recent Guruincsite malware issue. There are no confirmed reports of attacks related to these issues to-date, but it is important that you work with your clients to deploy the patch in order to protect their stores. More information about the patch is provided in the Magento Security Center and in the Magento Enterprise Edition and Magento Community Edition release notes.

BACKWARD COMPATIBILITY

This patch breaks backward compatibility in ways that can affect your client’s extensions or customizations (see notes for details). For example, an update to admin routing can make improperly coded extensions and customizations inaccessible from the admin panel. We expect that many extensions and customizations will be affected by this change, so we are releasing the patch with it included, but turned off. This lets merchants immediately benefit from the rest of the patch, while also giving them time to update their code before turning on the admin routing change.

We recommend that you and your clients first test the code in a non-production environment with the admin routing change turned on. If it works, deploy the fully-enabled patch to production. If you discover issues with accessing extensions or customizations from the admin panel, deploy the patch with the admin routing change disabled. Then work with your clients and their extension providers to update impacted customizations and extensions. We urge you to turn on the admin routing change as soon as possible to help protect your clients from automated attacks, like the malware issue we recently experienced.

DOWNLOADING THE SECURITY PATCH

Patches are available for Magento Enterprise Edition 1.7 and later releases and Magento Community Edition 1.4 and later releases. Before implementing this new security patch (SUPEE-6788), your clients must first implement all previous security patches. This will ensure that the patch works properly.

To download the patch, choose from the following options:

  • Enterprise Edition Merchants: Go to My Account, select the Downloads tab, and then navigate to Magento Enterprise Edition > Support Patches. Look for the folder titled “Security Patches – October 2015.” Merchants can also upgrade to Enterprise Edition 1.14.2.2 and receive the security update as part of the core code. 
  • Community Edition Merchants: Patches for earlier versions of Community Edition can be found on the Community Edition download page (look for SUPEE-6788). Merchants can also upgrade to Community Edition 1.9.2.2 and receive the security update as part of the core code. 

Information about installing patches for Magento Enterprise Edition and Magento Community Edition is available online.

Thank you for your attention and continued support.

Best regards,

The Magento Team

Screen Shot 2015-10-27 at 7.02.07 PM




Read This Next:




Just a moment...
Just a moment...