CVE-2021-21031: Magento Commerce Failure To Invalidate User Session Could Lead To Unauthorized Access
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) do not adequately invalidate user sessions. Successful exploitation could lead to unauthorized access to restricted resources. Access to the admin console is not required for successful exploitation.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-21031?
CVE-2021-21031 is a vulnerability in Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier), and 2.3.6 (and earlier) that allows unauthorized access to restricted resources due to inadequate invalidation of user sessions.
How severe is CVE-2021-21031?
CVE-2021-21031 has a severity rating of 5.6 (out of 10).
Which versions of Magento are affected by CVE-2021-21031?
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier), and 2.3.6 (and earlier) are affected by CVE-2021-21031.
How can CVE-2021-21031 be exploited?
Successful exploitation of CVE-2021-21031 could lead to unauthorized access to restricted resources, without requiring access to the admin console.
Where can I find more information about CVE-2021-21031?
More information about CVE-2021-21031 can be found at the following link: [https://helpx.adobe.com/security/products/magento/apsb21-08.html].