Bulletin ID
Security Updates Available for Magento | APSB21-08
|
Bulletin ID |
Date Published |
Priority |
|---|---|---|
|
ASPB21-08 |
February 09, 2021 |
2 |
| Product | Version | Platform |
|---|---|---|
Magento Commerce |
2.4.1 and earlier versions |
All |
| 2.4.0-p1 and earlier versions |
All | |
| 2.3.6 and earlier versions |
All |
|
| Magento Open Source |
2.4.1 and earlier versions |
All |
| 2.4.0-p1 and earlier versions |
All | |
| 2.3.6 and earlier versions |
All |
Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version.
| Product | Updated Version | Platform | Priority Rating | Release Notes |
|---|---|---|---|---|
| Magento Commerce |
2.4.2 |
All |
2 |
|
| 2.4.1-p1 |
All |
2 |
||
| 2.3.6-p1 | All |
2 |
||
| Magento Open Source |
2.4.2 |
All | 2 | |
| 2.4.1-p1 |
All | 2 | ||
| 2.3.6-p1 | All |
2 |
Pre-authentication: The vulnerability is exploitable without credentials.
Admin privileges required: The vulnerability is only exploitable by an attacker with administrative privileges.
Additional technical descriptions of the CVEs referenced in this document will be made available on MITRE and NVD sites.
|
Dependency |
Vulnerability Impact |
Affected Versions |
|---|---|---|
|
Angular |
Prototype Pollution |
2.4.2, 2.4.1-p1, 2.3.6-p1 |
Adobe would like to thank the following individuals for reporting the relevant issues and for working with Adobe to help protect our customers:
February 09, 2021: Updated acknowledgement details about CVE-2021-21014.
Bejelentkezés a fiókba