OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Custom Layout enabled admin users to execute arbitrary commands via block methods. Versions 19.4.22 and 20.0.19 contain patches for this issue.
References
| Link | Resource |
|---|---|
| https://github.com/OpenMage/magento-lts/commit/289bd4b4f53622138e3e5c2d2cef7502d780086f | Patch Third Party Advisory |
| https://github.com/OpenMage/magento-lts/releases/tag/v19.4.22 | Release Notes Third Party Advisory |
| https://github.com/OpenMage/magento-lts/releases/tag/v20.0.19 | Release Notes Third Party Advisory |
| https://github.com/OpenMage/magento-lts/security/advisories/GHSA-c9q3-r4rv-mjm7 | Third Party Advisory |
| https://github.com/OpenMage/magento-lts/commit/289bd4b4f53622138e3e5c2d2cef7502d780086f | Patch Third Party Advisory |
| https://github.com/OpenMage/magento-lts/releases/tag/v19.4.22 | Release Notes Third Party Advisory |
| https://github.com/OpenMage/magento-lts/releases/tag/v20.0.19 | Release Notes Third Party Advisory |
| https://github.com/OpenMage/magento-lts/security/advisories/GHSA-c9q3-r4rv-mjm7 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2023-01-27 18:15
Updated : 2024-11-21 06:18
NVD link : CVE-2021-39217
Mitre link : CVE-2021-39217
CVE.ORG link : CVE-2021-39217
JSON object : View
Products Affected
openmage
- magento
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
