PT-2021-1823 · Adobe · Magento+1

Published

2021-01-12

·

Updated

2022-08-05

·

CVE-2021-21013

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Magento versions 2.4.1 and earlier Magento versions 2.4.0-p1 and earlier Magento versions 2.3.6 and earlier Adobe Bridge (affected versions not specified)
Description: The issue is related to a mechanism flaw in the customer API module of Magento Commerce, which can be exploited to gain unauthorized access to protected information. Successful exploitation could lead to sensitive information disclosure and update arbitrary information on another user's account. Additionally, there is a buffer overflow vulnerability in Adobe Bridge that can be exploited to execute arbitrary code in the context of the current user using a specially crafted file.
Recommendations: For Magento versions 2.4.1 and earlier, update to a version that addresses the insecure direct object vulnerability in the customer API module. For Magento versions 2.4.0-p1 and earlier, update to a version that addresses the insecure direct object vulnerability in the customer API module. For Magento versions 2.3.6 and earlier, update to a version that addresses the insecure direct object vulnerability in the customer API module. For Adobe Bridge, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

IDOR

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2021-00580
BDU:2021-01090
CVE-2021-21013

Affected Products

Bridge
Magento