First published: Thu Feb 11 2021(Updated: )
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object reference (IDOR) in the product module. Successful exploitation could lead to unauthorized access to restricted resources.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/magento/community-edition | >=2.4.0<2.4.1-p1 | 2.4.1-p1 |
composer/magento/community-edition | <2.3.6-p1 | 2.3.6-p1 |
Magento Magento | <2.3.6 | |
Magento Magento | <2.3.6 | |
Magento Magento | =2.3.6 | |
Magento Magento | =2.3.6 | |
Magento Magento | =2.4.0 | |
Magento Magento | =2.4.0 | |
Magento Magento | =2.4.0-p1 | |
Magento Magento | =2.4.0-p1 | |
Magento Magento | =2.4.1 | |
Magento Magento | =2.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21022 is a vulnerability in Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) that allows for an insecure direct object reference (IDOR) in the product module, potentially leading to unauthorized access to restricted resources.
CVE-2021-21022 has a severity level of 5.3 out of 10, which is considered medium.
To fix CVE-2021-21022, you should update your Magento installation to version 2.4.2 (or later) if you are using Magento Commerce, or version 2.3.7 (or later) if you are using Magento Open Source.
No, only Magento versions 2.4.1 and earlier, 2.4.0-p1 and earlier, and 2.3.6 and earlier are affected by CVE-2021-21022.
You can find more information about CVE-2021-21022 on the Adobe Security Bulletin APSB21-08.