CVE-2021-36012: Magento Commerce Gift Card Business Logic Error
Published Sep 1, 2021
·Updated
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a business logic error in the placeOrder graphql mutation. An authenticated attacker can leverage this vulnerability to altar the price of an item.
Affected Software
6 affected components
Adobe Adobe Commerce>=2.3.0<=2.3.7
Adobe Adobe Commerce>=2.4.0<=2.4.2
Adobe Adobe Commerce=2.4.2-p1
Adobe Magento Open Source>=2.3.0<=2.3.7
Adobe Magento Open Source>=2.4.0<=2.4.2
Adobe Magento Open Source=2.4.2-p1
Remediation
Event History
Sep 1, 2021
CVE Published
via MITRE·02:28 PM
Data Sourced
via MITRE·02:28 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-36012.
2
What is the severity of CVE-2021-36012?
The severity of CVE-2021-36012 is medium (6.5).
3
Which versions of Magento Commerce are affected by CVE-2021-36012?
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier), and 2.3.7 (and earlier) are affected by CVE-2021-36012.
4
What is the impact of CVE-2021-36012?
An authenticated attacker can leverage this vulnerability to alter the price of an item.
5
Is there a fix available for CVE-2021-36012?
Yes, a fix is available for CVE-2021-36012. Update to Magento Commerce versions 2.4.3, 2.4.2-p2, or 2.3.8.