CVE-2021-41144: OpenMage LTS authenticated remote code execution through layout update
OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, a layout block was able to bypass the block blacklist to execute remote code. Versions 19.4.22 and 20.0.19 contain a patch for this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-41144?
CVE-2021-41144 is a vulnerability in OpenMage LTS, an e-commerce platform, that allows a layout block to bypass the block blacklist and execute remote code.
What versions of OpenMage LTS are affected by CVE-2021-41144?
Versions prior to 19.4.22 and 20.0.19 of OpenMage LTS are affected by CVE-2021-41144.
How severe is the CVE-2021-41144 vulnerability?
CVE-2021-41144 has a severity rating of high with a CVSS score of 8.8.
How can I fix CVE-2021-41144?
To fix CVE-2021-41144, update your OpenMage LTS installation to versions 19.4.22 or 20.0.19 which contain the patch for this vulnerability.
Where can I find more information about CVE-2021-41144?
You can find more information about CVE-2021-41144 on the following references: [Reference 1](https://github.com/OpenMage/magento-lts/commit/06c45940ba3256cdfc9feea12a3c0ca56d23acf8), [Reference 2](https://github.com/OpenMage/magento-lts/releases/tag/v19.4.22), [Reference 3](https://github.com/OpenMage/magento-lts/releases/tag/v20.0.19).