CVE-2021-41231
Prior to versions 19.4.22 and 20.0.19, an administrator with the permissions to upload files via DataFlow and to create products was able to execute arbitrary code via the convert profile.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.23%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, an administrator with the permissions to upload files via DataFlow and to create products was able to execute arbitrary code via the convert profile. Versions 19.4.22 and 20.0.19 contain a patch for this issue.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.23% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-77, CWE-434
- Affected
- openmage/magento
- Source
- security-advisories@github.com
References
- https://github.com/OpenMage/magento-lts/commit/d16fc6c5a1e66c6f0d9f82020f11702a7ddd78e4Patch, Third Party Advisory
- https://github.com/OpenMage/magento-lts/releases/tag/v19.4.22Release Notes, Third Party Advisory
- https://github.com/OpenMage/magento-lts/releases/tag/v20.0.19Release Notes, Third Party Advisory
- https://github.com/OpenMage/magento-lts/security/advisories/GHSA-h632-p764-pjqmThird Party Advisory
- https://github.com/OpenMage/magento-lts/commit/d16fc6c5a1e66c6f0d9f82020f11702a7ddd78e4Patch, Third Party Advisory
- https://github.com/OpenMage/magento-lts/releases/tag/v19.4.22Release Notes, Third Party Advisory
- https://github.com/OpenMage/magento-lts/releases/tag/v20.0.19Release Notes, Third Party Advisory
- https://github.com/OpenMage/magento-lts/security/advisories/GHSA-h632-p764-pjqmThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.