CVE-2021-36044: Magento Commerce GraphQL Improper Input Validation Could Lead To Denial Of Service
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An unauthenticated attacker could abuse this vulnerability to cause a server-side denial-of-service using a GraphQL field.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-36044?
CVE-2021-36044 is a vulnerability affecting Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier), and 2.3.7 (and earlier).
How does CVE-2021-36044 impact Magento Commerce?
CVE-2021-36044 can be exploited by an unauthenticated attacker to cause a server-side denial-of-service using a GraphQL field.
What is the severity of CVE-2021-36044?
The severity of CVE-2021-36044 is high, with a CVSS score of 7.5.
Which versions of Magento Commerce are affected by CVE-2021-36044?
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier), and 2.3.7 (and earlier) are affected by CVE-2021-36044.
Is there a fix available for CVE-2021-36044?
Yes, Adobe has released a security advisory with patches and mitigation steps to address CVE-2021-36044. Please refer to the reference link for more information.