PT-2021-2300 · Adobe · Magento

Published

2021-02-09

·

Updated

2024-03-06

·

CVE-2021-21031

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Magento versions 2.4.1 and earlier Magento versions 2.4.0-p1 and earlier Magento versions 2.3.6 and earlier
Description The issue is related to the lack of automatic termination of all sessions after a password change, which could allow a remote attacker to gain unauthorized access to restricted resources. Successful exploitation does not require access to the admin console.
Recommendations For versions 2.4.1 and earlier, update to a version that adequately invalidates user sessions after a password change. For versions 2.4.0-p1 and earlier, update to a version that adequately invalidates user sessions after a password change. For versions 2.3.6 and earlier, update to a version that adequately invalidates user sessions after a password change. As a temporary workaround, consider manually terminating all user sessions after a password change until a patch is available.

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

BDU:2021-01534
BIT-MAGENTO-2021-21031
CVE-2021-21031
GHSA-4H3P-63X6-VWG2

Affected Products

Magento