PT-2021-6290 · Adobe · Magento Commerce

Published

2021-08-11

·

Updated

2022-10-24

·

CVE-2021-36032

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Magento Commerce versions 2.4.2 and earlier Magento Commerce versions 2.4.2-p1 and earlier Magento Commerce versions 2.3.7 and earlier
Description The issue exists due to insufficient input validation in the Magento Commerce platform, allowing a remote attacker to escalate their privileges. An authenticated attacker can trigger an insecure direct object reference in the "V1/customers/me" endpoint to achieve information exposure and privilege escalation.
Recommendations For Magento Commerce versions 2.4.2 and earlier, update to a version that includes the fix for the improper input validation vulnerability. For Magento Commerce versions 2.4.2-p1 and earlier, update to a version that includes the fix for the improper input validation vulnerability. For Magento Commerce versions 2.3.7 and earlier, update to a version that includes the fix for the improper input validation vulnerability. As a temporary workaround, consider restricting access to the V1/customers/me endpoint to minimize the risk of exploitation.

Fix

IDOR

RCE

Weakness Enumeration

Related Identifiers

BDU:2022-01262
CVE-2021-36032
GHSA-5VW8-R55W-F4Q4

Affected Products

Magento Commerce