PT-2021-14498 · Unknown · Zend Framework+1
Highflyingmana
·
Published
2021-04-21
·
Updated
2021-04-30
·
CVE-2021-21426
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
magento-lts versions 19.4.12 and prior
magento-lts versions 20.0.8 and prior
Description
The issue is caused by the unsecured deserialization of an object. A patch was back ported from Zend Framework 3 to resolve the issue.
Recommendations
For magento-lts versions 19.4.12 and prior, update to version 19.4.13 or later.
For magento-lts versions 20.0.8 and prior, update to version 20.0.9 or later.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zend Framework
Magento-Lts