CVE-2021-36043: Magento Commerce Authenticated Blind SSRF Could Lead To Remote Code Execution
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a blind SSRF vulnerability in the bundled dotmailer extension. An attacker with admin privileges could abuse this to achieve remote code execution should Redis be enabled.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-36043?
CVE-2021-36043 is a blind SSRF vulnerability in the bundled dotmailer extension in Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier), and 2.3.7 (and earlier).
How does CVE-2021-36043 affect Magento Commerce?
CVE-2021-36043 affects Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier), and 2.3.7 (and earlier) through a blind SSRF vulnerability in the bundled dotmailer extension.
What can an attacker achieve with CVE-2021-36043?
An attacker with admin privileges could abuse CVE-2021-36043 to achieve remote code execution if Redis is enabled.
How severe is CVE-2021-36043?
CVE-2021-36043 has a severity rating of high with a CVSS score of 6.6.
How can I fix CVE-2021-36043?
To fix CVE-2021-36043, update Magento Commerce to versions 2.4.2-p1, 2.3.8, or 2.4.3 or apply the provided patches.