Skip to content

Backport for CVE-2021-21024 Blind SQLi from Magento 2

High
Flyingmana published GHSA-fvrf-9428-527m Apr 20, 2021

Package

No package listed

Affected versions

< v20.0.8 v19.4.12

Patched versions

> v20.0.9 v19.4.13

Description

Impact

This vulnerability allows an administrator unauthorized access to restricted resources.

We fixed a vulnerability in the MySQL adapter to prevent SQL injection attacks. This is a backport of CVE-2021-21024 https://helpx.adobe.com/security/products/magento/apsb21-08.html.

Patches

Has the problem been patched? What versions should users upgrade to?

v20.0.9 v19.4.13

Severity

High

CVE ID

CVE-2021-21427

Weaknesses

No CWEs