PT-2021-2309 · Adobe · Magento

CVE-2021-21026

·

Published

2021-02-09

·

Updated

2024-03-06

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Magento versions 2.4.1 and earlier Magento versions 2.4.0-p1 and earlier Magento versions 2.3.6 and earlier
Description The issue is related to improper authorization in the integrations module of Magento Commerce, which can be exploited by a remote attacker to gain unauthorized access to protected information. This can be achieved by accessing the admin console.
Recommendations For versions 2.4.1 and earlier, update to a version that includes the fix for the improper authorization vulnerability. For versions 2.4.0-p1 and earlier, update to a version that includes the fix for the improper authorization vulnerability. For versions 2.3.6 and earlier, update to a version that includes the fix for the improper authorization vulnerability.

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01543
BIT-MAGENTO-2021-21026
CVE-2021-21026
GHSA-CRJC-2V9M-8W7R

Affected Products

Magento