Security Updates Available for Magento | APSB21-08
| Product | Version | Platform |
|---|---|---|
Magento Commerce |
2.4.1 and earlier versions |
All |
| 2.4.0-p1 and earlier versions |
All | |
| 2.3.6 and earlier versions |
All |
|
| Magento Open Source |
2.4.1 and earlier versions |
All |
| 2.4.0-p1 and earlier versions |
All | |
| 2.3.6 and earlier versions |
All |
Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version.
| Product | Updated Version | Platform | Priority Rating | Release Notes |
| Magento Commerce |
2.4.2 |
All |
2 |
|
| 2.4.1-p1 |
All |
2 |
||
| 2.3.6-p1 | All |
2 |
||
| Magento Open Source |
2.4.2 |
All | 2 | |
| 2.4.1-p1 |
All | 2 | ||
| 2.3.6-p1 | All |
2 |
Note
Pre-authentication: The vulnerability is exploitable without credentials.
Admin privileges required: The vulnerability is only exploitable by an attacker with administrative privileges.
Additional technical descriptions of the CVEs referenced in this document will be made available on MITRE and NVD sites.
| Dependency | Vulnerability Impact | Affected Versions |
| Angular |
Prototype Pollution |
2.4.2, 2.4.1-p1, 2.3.6-p1 |
Adobe would like to thank the following individuals for reporting the relevant issues and for working with Adobe to help protect our customers:
- Malerisch (CVE-2021-21012)
- Niels Pijpers (CVE-2021-21013)
- Blaklis (CVE-2021-21014, CVE-2021-21018, CVE-2021-21030)
- Kien Hoang (hoangkien1020) (CVE-2021-21014)
- Edgar Boda-Majer of Bugscale (CVE-2021-21015, CVE-2021-21016, CVE-2021-21022)
- Kien Hoang (CVE-2021-21020)
- bobbytabl35_ (CVE-2021-21023)
- Wohlie (CVE-2021-21024)
- Peter O'Callaghan (CVE-2021-21025)
- Kiên Ka Lư (CVE-2021-21026)
- Lachlan Davidson (CVE-2021-21027)
- Natsasit Jirathammanuwat (Office Thailand) working with SEC Consult Vulnerability Lab (CVE-2021-21029)
- Anas (CVE-2021-21031)
