CVE-2021-28585: Magento Commerce improper input validation in customer customer webapi
Published Jun 28, 2021
·Updated
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by an Improper input validation vulnerability in the New customer WebAPI.Successful exploitation could allow an attacker to send unsolicited spam e-mails.
Affected Software
15 affected componentsFixes available
composer/magento/project-community-edition<=2.0.2
composer/magento/community-edition>=2.4.0<2.4.2-p1
2.4.2-p1
composer/magento/community-edition<2.3.7
2.3.7
Magento Magento<2.3.6
Magento Magento<2.3.6
Magento Magento=2.3.6
Magento Magento=2.3.6
Magento Magento=2.3.6-p1
Magento Magento=2.3.6-p1
Magento Magento=2.4.1
Magento Magento=2.4.1
Magento Magento=2.4.1-p1
Magento Magento=2.4.1-p1
Magento Magento=2.4.2
Magento Magento=2.4.2
Remediation
Event History
Jun 28, 2021
CVE Published
via MITRE·01:47 PM
Data Sourced
via MITRE·01:47 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 24, 2022
Advisory Published
via GitHub·07:06 PM
Frequently Asked Questions
1
What is the vulnerability ID for this Magento vulnerability?
The vulnerability ID for this Magento vulnerability is CVE-2021-28585.
2
What is the severity of CVE-2021-28585?
The severity of CVE-2021-28585 is medium (5.3).
3
Which versions of Magento are affected by CVE-2021-28585?
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier), and 2.3.6-p1 (and earlier) are affected by CVE-2021-28585.
4
What is the impact of CVE-2021-28585?
Successful exploitation of CVE-2021-28585 could allow an attacker to send unsolicited spam e-mails.
5
Where can I find more information about CVE-2021-28585?
You can find more information about CVE-2021-28585 at the following link: [link](https://helpx.adobe.com/security/products/magento/apsb21-30.html)