CVE-2021-28583

Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Violation of Secure Design Principles vulnerability in RMA PDF filename formats. Successful exploitation could allow an attacker to get unauthorized access to restricted resources.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*
cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*
cpe:2.3:a:magento:magento:2.3.6:-:*:*:commerce:*:*:*
cpe:2.3:a:magento:magento:2.3.6:-:*:*:open_source:*:*:*
cpe:2.3:a:magento:magento:2.3.6:p1:*:*:commerce:*:*:*
cpe:2.3:a:magento:magento:2.3.6:p1:*:*:open_source:*:*:*
cpe:2.3:a:magento:magento:2.4.1:-:*:*:commerce:*:*:*
cpe:2.3:a:magento:magento:2.4.1:-:*:*:open_source:*:*:*
cpe:2.3:a:magento:magento:2.4.1:p1:*:*:commerce:*:*:*
cpe:2.3:a:magento:magento:2.4.1:p1:*:*:open_source:*:*:*
cpe:2.3:a:magento:magento:2.4.2:*:*:*:commerce:*:*:*
cpe:2.3:a:magento:magento:2.4.2:*:*:*:open_source:*:*:*

Information

Published : 2021-06-28 07:15

Updated : 2021-07-06 13:04


NVD link : CVE-2021-28583

Mitre link : CVE-2021-28583


JSON object : View

CWE
CWE-657

Violation of Secure Design Principles

Advertisement

dedicated server usa

Products Affected

magento

  • magento