PT-2021-14498 · Unknown · Zend Framework+1

Highflyingmana

·

Published

2021-04-21

·

Updated

2021-04-30

·

CVE-2021-21426

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions magento-lts versions 19.4.12 and prior magento-lts versions 20.0.8 and prior
Description The issue is caused by the unsecured deserialization of an object. A patch was back ported from Zend Framework 3 to resolve the issue.
Recommendations For magento-lts versions 19.4.12 and prior, update to version 19.4.13 or later. For magento-lts versions 20.0.8 and prior, update to version 20.0.9 or later.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-21426
GHSA-M496-X567-F98C

Affected Products

Zend Framework
Magento-Lts