CVE-2021-36029: Magento Commerce Improper Authorization Vulnerability Could Lead To Remote Code Execution
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper improper authorization vulnerability. An attacker with admin privileges could leverage this vulnerability to achieve remote code execution.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-36029?
The severity of CVE-2021-36029 is critical with a CVSS score of 7.2.
How does CVE-2021-36029 affect Magento Commerce?
CVE-2021-36029 affects Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier), and 2.3.7 (and earlier).
What is the vulnerability in CVE-2021-36029?
CVE-2021-36029 is an improper authorization vulnerability that allows an attacker with admin privileges to achieve remote code execution.
How can an attacker exploit CVE-2021-36029?
An attacker with admin privileges can exploit CVE-2021-36029 to achieve remote code execution.
Is there a fix available for CVE-2021-36029?
Yes, a fix is available for CVE-2021-36029. Refer to the vendor's security advisory for more information.