CVE-2021-21022
Magento Commerce Incorrect permissions Could Lead To Unauthorized Access
5.3
MEDIUM
CVSS 3.1
EPSS 0.15%
Description
Magento versions 2.4.1 (and earlier), 2.4.0 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object reference (IDOR) in the product module. Successful exploitation could lead to unauthorized access to restricted resources.
How to fix CVE-2021-21022
To remediate CVE-2021-21022, upgrade the affected package to a fixed version below.
- —upgrade to 2.3.6 or later
- —upgrade to 2.3.6-p1 or later
- —no fix listed
Is CVE-2021-21022 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 2.3.6, >= 2.4.0, < 2.4.1
- from 0, < 2.3.6-p1
- from 0, <= 2.0.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |