PT-2021-2309 · Adobe · Magento

Published

2021-02-09

·

Updated

2024-03-06

·

CVE-2021-21026

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Magento versions 2.4.1 and earlier Magento versions 2.4.0-p1 and earlier Magento versions 2.3.6 and earlier
Description The issue is related to improper authorization in the integrations module of Magento Commerce, which can be exploited by a remote attacker to gain unauthorized access to protected information. This can be achieved by accessing the admin console.
Recommendations For versions 2.4.1 and earlier, update to a version that includes the fix for the improper authorization vulnerability. For versions 2.4.0-p1 and earlier, update to a version that includes the fix for the improper authorization vulnerability. For versions 2.3.6 and earlier, update to a version that includes the fix for the improper authorization vulnerability.

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

BDU:2021-01543
BIT-MAGENTO-2021-21026
CVE-2021-21026
GHSA-CRJC-2V9M-8W7R

Affected Products

Magento