CVE-2021-21012: Magento Commerce Insecure Direct Object Reference Vulnerability Could Lead To Sensitive Information Disclosure
Published Jan 13, 2021
·Updated
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object vulnerability (IDOR) in the checkout module. Successful exploitation could lead to sensitive information disclosure.
Affected Software
8 affected components
Adobe Magento Commerce<=2.3.6
Adobe Magento Commerce=2.4.0
Adobe Magento Commerce=2.4.0-p1
Adobe Magento Commerce=2.4.1
Adobe Magento Open Source<=2.3.6
Adobe Magento Open Source=2.4.0
Adobe Magento Open Source=2.4.0-p1
Adobe Magento Open Source=2.4.1
Event History
Jan 13, 2021
CVE Published
via MITRE·10:35 PM
Data Sourced
via MITRE·10:35 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Magento vulnerability?
The vulnerability ID for this Magento vulnerability is CVE-2021-21012.
2
Which versions of Magento are affected by this vulnerability?
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier), and 2.3.6 (and earlier) are affected by this vulnerability.
3
What is the severity level of vulnerability CVE-2021-21012?
The severity level of vulnerability CVE-2021-21012 is medium (CVSS score of 5.3).
4
What is the type of vulnerability for CVE-2021-21012?
CVE-2021-21012 is an insecure direct object reference (IDOR) vulnerability.
5
How can this vulnerability be exploited?
Successful exploitation of this vulnerability could lead to sensitive information disclosure.