{"id":5197,"date":"2019-04-05T10:31:29","date_gmt":"2019-04-05T15:31:29","guid":{"rendered":"https:\/\/3dmerchant.com\/blog\/?p=5197"},"modified":"2021-12-03T03:25:06","modified_gmt":"2021-12-03T08:25:06","slug":"magento-security-alert-requires-action-to-maintain-pci-compliance","status":"publish","type":"post","link":"https:\/\/3dmerchant.com\/blog\/merchant-processing-security\/magento-security-alert-requires-action-to-maintain-pci-compliance","title":{"rendered":"Magento Security Alert requires action to maintain PCI Compliance"},"content":{"rendered":"\n<h1 class=\"wp-block-heading\">Magento 2.3.1, 2.2.8 and 2.1.17 Security Update<\/h1>\n\n\n\n<p><strong>A SQL injection vulnerability has been identified in pre-2.3.1  Magento code. To quickly protect your store from this vulnerability  only, install patch PRODSECBUG-2198. However, to protect against this  vulnerability and others, you must upgrade to Magento Commerce or Open  Source 2.3.1 or 2.2.8. <em>We strongly suggest that you install these full patches as soon as you can<\/em>.<\/strong><\/p>\n\n\n\n<p><strong>PCI Compliance Requirement 6: Develop and maintain secure systems and applications<\/strong>. <strong>All critical systems must have the most recently released software patches to prevent exploitation. <\/strong>\n The average merchant relies upon third party developers for web site \nmaintenance, but unless specifically contracted to update the e-commerce\n software and add-on modules, don\u2019t count on it.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>Only 16.4% of organizations that had suffered a data \nbreach were compliant with Requirement 6, compared to an average of 64% \nof organizations assessed by our QSAs in 2014- Verizon 2015 PCI \nCompliance Report.<\/p><\/blockquote>\n\n\n\n<p>Payment gateway implementation requirements have changed over time as  a result of cross-site scripting and cross-site request forgery (CSRF)  to meet current PCI Compliance standards. Merchants should verify all  components of their ecommerce ecosystem are current, and have a system  for ongoing monitoring and updating.<\/p>\n\n\n\n<p>RESOURCES<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><a rel=\"noreferrer noopener\" href=\"http:\/\/magento.com\/security\" target=\"_blank\">Magento Security Center<\/a><\/li><li><a rel=\"noreferrer noopener\" aria-label=\"MAGENTO SECURITY ALERT (opens in a new tab)\" href=\"https:\/\/magento.com\/security\/patches\/magento-2.3.1-2.2.8-and-2.1.17-security-update\" target=\"_blank\">MAGENTO SECURITY ALERT<\/a>, March 26, 2019<\/li><li><a rel=\"noreferrer noopener\" href=\"https:\/\/3dmerchant.com\/blog\/about\" target=\"_blank\"><em>Christine Speedy<\/em><\/a><em>, 3D Merchant Services, offers a Magento <strong>payment gateway <\/strong>module  for merchants to improve their omnichannel customer experience and mitigate fraud and vulnerability risk. Special B2B customer benefits include friction-less payments  across all sales channels; text and email Express Checkout, customer  invoice portal for 24\/7 ACH, credit card, wire and more payment types,  and US <a href=\"https:\/\/3dmerchant.com\/blog\/merchant-processing-security\/emv-knowledgebase-mandates\">EMV<\/a> with <\/em><a rel=\"noreferrer noopener\" href=\"https:\/\/3dmerchant.com\/blog\/credit-card-processing-rates\/cloud-payment-technology\" target=\"_blank\"><em>level 3 processing<\/em><\/a><em>.  Magento and ERP modules combine to provide a powerful array of  solutions to improve cash flow and profits while maximizing security.  954-942-0483.<\/em><\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Magento 2.3.1, 2.2.8 and 2.1.17 Security Update A SQL injection vulnerability has been identified in pre-2.3.1 Magento code. To quickly protect your store from this vulnerability only, install patch PRODSECBUG-2198. However, to protect against this vulnerability and others, you must &hellip; <a href=\"https:\/\/3dmerchant.com\/blog\/merchant-processing-security\/magento-security-alert-requires-action-to-maintain-pci-compliance\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":11,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[33,9],"tags":[186,39],"class_list":["post-5197","post","type-post","status-publish","format-standard","hentry","category-ecommerce","category-merchant-processing-security","tag-magento","tag-pci-compliance"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/3dmerchant.com\/blog\/wp-json\/wp\/v2\/posts\/5197","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/3dmerchant.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/3dmerchant.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/3dmerchant.com\/blog\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/3dmerchant.com\/blog\/wp-json\/wp\/v2\/comments?post=5197"}],"version-history":[{"count":1,"href":"https:\/\/3dmerchant.com\/blog\/wp-json\/wp\/v2\/posts\/5197\/revisions"}],"predecessor-version":[{"id":5198,"href":"https:\/\/3dmerchant.com\/blog\/wp-json\/wp\/v2\/posts\/5197\/revisions\/5198"}],"wp:attachment":[{"href":"https:\/\/3dmerchant.com\/blog\/wp-json\/wp\/v2\/media?parent=5197"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/3dmerchant.com\/blog\/wp-json\/wp\/v2\/categories?post=5197"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/3dmerchant.com\/blog\/wp-json\/wp\/v2\/tags?post=5197"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}