CVE-2021-21020: Magento Commerce Improper Access Control Vulnerability
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an access control bypass vulnerability in the Login as Customer module. Successful exploitation could lead to unauthorized access to restricted resources.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this specific vulnerability?
The vulnerability ID for this specific vulnerability is CVE-2021-21020.
What is the severity of CVE-2021-21020?
The severity of CVE-2021-21020 is medium with a severity score of 5.3.
What versions of Magento are affected by CVE-2021-21020?
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier), and 2.3.6 (and earlier) are affected by CVE-2021-21020.
What is the impact of CVE-2021-21020?
The impact of CVE-2021-21020 is an access control bypass vulnerability in the Login as Customer module, which could lead to unauthorized access to restricted resources.
Is there a fix available for CVE-2021-21020?
Yes, a fix is available for CVE-2021-21020. It is recommended to upgrade to the latest patched version of Magento.